{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "author": "https://tuxcare.com",
  "role": "Document Creator",
  "timestamp": "2026-10-02T19:19:00.191036+00:00",
  "version": 1,
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@23.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@23.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27448 is fixed in version 23.3.0.post1+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27448"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@23.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@23.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27459 is fixed in version 23.3.0.post1+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@24.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@24.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27448 is fixed in version 24.3.0.post1+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27448"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@24.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@24.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27459 is fixed in version 24.3.0.post1+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 affects version 2.9.1.post8+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      },
      "action_statement": "Vulnerability CVE-2023-6940 affects version 2.9.1.post8+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post8+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post8+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 affects version 2.9.1.post8+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      },
      "action_statement": "Vulnerability CVE-2024-37054 affects version 2.9.1.post8+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post8+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post8+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post8+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post8+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post8+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post8+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post8+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post8+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post8+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post8+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post8+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post8+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post8+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post8+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.9.1.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post8+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post8+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post8+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/anyio@3.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/anyio@3.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10170 is fixed in version 3.7.1.post2+tuxcare of anyio.",
      "vulnerability": {
        "name": "AIKIDO-2025-10170"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/anyio@3.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/anyio@3.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-63374 is fixed in version 3.7.1.post2+tuxcare of anyio.",
      "vulnerability": {
        "name": "CVE-2026-63374"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/anyio@3.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/anyio@3.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64847 is fixed in version 3.7.1.post2+tuxcare of anyio.",
      "vulnerability": {
        "name": "CVE-2026-64847"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6839 affects version 4.0.2.post1+tuxcare of flask-cors, and is fixed in 4.0.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-6839"
      },
      "action_statement": "Vulnerability CVE-2024-6839 affects version 4.0.2.post1+tuxcare of flask-cors, and is fixed in 4.0.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6844 affects version 4.0.2.post1+tuxcare of flask-cors, and is fixed in 4.0.2.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-6844"
      },
      "action_statement": "Vulnerability CVE-2024-6844 affects version 4.0.2.post1+tuxcare of flask-cors, and is fixed in 4.0.2.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6866 is fixed in version 4.0.2.post1+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6866"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/idna@2.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/idna@2.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3651 is fixed in version 2.10.post1+tuxcare of idna.",
      "vulnerability": {
        "name": "CVE-2024-3651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/idna@2.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/idna@2.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45409 affects version 2.10.post1+tuxcare of idna.",
      "vulnerability": {
        "name": "CVE-2026-45409"
      },
      "action_statement": "Vulnerability CVE-2026-45409 affects version 2.10.post1+tuxcare of idna."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48379 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2025-48379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 11.2.1.post4+tuxcare of pillow, and is fixed in 11.2.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 11.2.1.post4+tuxcare of pillow, and is fixed in 11.2.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 11.2.1.post4+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 11.2.1.post4+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 11.2.1.post4+tuxcare of pillow, and is fixed in 11.2.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 11.2.1.post4+tuxcare of pillow, and is fixed in 11.2.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 11.2.1.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 is fixed in version 46.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 is fixed in version 46.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 46.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 46.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/piexif@1.1.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/piexif@1.1.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability SNYK-PYTHON-PIEXIF-2312874 is fixed in version 1.1.3.post1+tuxcare of piexif.",
      "vulnerability": {
        "name": "SNYK-PYTHON-PIEXIF-2312874"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33430 affects version 1.16.0.post1+tuxcare of numpy, and is fixed in 1.16.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-33430"
      },
      "action_statement": "Vulnerability CVE-2021-33430 affects version 1.16.0.post1+tuxcare of numpy, and is fixed in 1.16.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-34141 affects version 1.16.0.post1+tuxcare of numpy, and is fixed in 1.16.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-34141"
      },
      "action_statement": "Vulnerability CVE-2021-34141 affects version 1.16.0.post1+tuxcare of numpy, and is fixed in 1.16.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41495 affects version 1.16.0.post1+tuxcare of numpy, and is fixed in 1.16.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-41495"
      },
      "action_statement": "Vulnerability CVE-2021-41495 affects version 1.16.0.post1+tuxcare of numpy, and is fixed in 1.16.0.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@70.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@70.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 is fixed in version 70.3.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@70.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@70.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 affects version 70.3.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      },
      "action_statement": "Vulnerability CVE-2026-59890 affects version 70.3.0.post1+tuxcare of setuptools."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-32681 affects version 2.30.0.post2+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-32681"
      },
      "action_statement": "Vulnerability CVE-2023-32681 affects version 2.30.0.post2+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-35195 affects version 2.30.0.post2+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-35195"
      },
      "action_statement": "Vulnerability CVE-2024-35195 affects version 2.30.0.post2+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 affects version 2.30.0.post2+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      },
      "action_statement": "Vulnerability CVE-2024-47081 affects version 2.30.0.post2+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 is fixed in version 2.30.0.post2+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@24.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@24.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27448 is fixed in version 24.3.0.post2+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27448"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@24.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@24.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27459 is fixed in version 24.3.0.post2+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 affects version 0.27.0.post5+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      },
      "action_statement": "Vulnerability CVE-2024-24762 affects version 0.27.0.post5+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post5+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 is fixed in version 0.27.0.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 is fixed in version 0.27.0.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 affects version 0.27.0.post5+tuxcare of starlette, and is fixed in 0.27.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      },
      "action_statement": "Vulnerability CVE-2026-54282 affects version 0.27.0.post5+tuxcare of starlette, and is fixed in 0.27.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 is fixed in version 0.27.0.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/redis@4.5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/redis@4.5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28858 is fixed in version 4.5.1.post1+tuxcare of redis.",
      "vulnerability": {
        "name": "CVE-2023-28858"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/redis@4.5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/redis@4.5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28859 is fixed in version 4.5.1.post1+tuxcare of redis.",
      "vulnerability": {
        "name": "CVE-2023-28859"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 44.0.3.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 44.0.3.post2+tuxcare of cryptography, and is fixed in 44.0.3.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 44.0.3.post2+tuxcare of cryptography, and is fixed in 44.0.3.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 affects version 44.0.3.post2+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      },
      "action_statement": "Vulnerability CVE-2026-69247 affects version 44.0.3.post2+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 44.0.3.post2+tuxcare of cryptography, and is fixed in 44.0.3.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 44.0.3.post2+tuxcare of cryptography, and is fixed in 44.0.3.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 44.0.3.post2+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 44.0.3.post2+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 44.0.3.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 42.0.8.post1+tuxcare of cryptography, and is fixed in 42.0.8.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 42.0.8.post1+tuxcare of cryptography, and is fixed in 42.0.8.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 42.0.8.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 42.0.8.post1+tuxcare of cryptography."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 42.0.8.post1+tuxcare of cryptography. not_affected \u2014 Target version 42.0.8.post2+tuxcare is NOT affected by CVE-2026-69248. The vulnerability requires wildcard DNS SAN support in name constraint validation, which was introduced in upstream commit 286c89128 (Jan 7, 2025) and fixed in commit 91d728897 (Mar 25, 2026, also known as CVE-2026-34073). The 42.x branch never received the vulnerable wildcard support code. Instead, this version uses the old...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 Target version 42.0.8.post2+tuxcare is NOT affected by CVE-2026-69248. The vulnerability requires wildcard DNS SAN support in name constraint validation, which was introduced in upstream commit 286c89128 (Jan 7, 2025) and fixed in commit 91d728897 (Mar 25, 2026, also known as CVE-2026-34073). The 42.x branch never received the vulnerable wildcard support code. Instead, this version uses the old..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 42.0.8.post1+tuxcare of cryptography, and is fixed in 42.0.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 42.0.8.post1+tuxcare of cryptography, and is fixed in 42.0.8.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 42.0.8.post1+tuxcare of cryptography, and is fixed in 42.0.8.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 42.0.8.post1+tuxcare of cryptography, and is fixed in 42.0.8.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@1.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@1.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30861 is fixed in version 1.1.4.post2+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2023-30861"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/flask@1.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@1.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27205 affects version 1.1.4.post2+tuxcare of flask, and is fixed in 1.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27205"
      },
      "action_statement": "Vulnerability CVE-2026-27205 affects version 1.1.4.post2+tuxcare of flask, and is fixed in 1.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.0.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.0.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1135 affects version 20.0.4.post2+tuxcare of gunicorn, and is fixed in 20.0.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1135"
      },
      "action_statement": "Vulnerability CVE-2024-1135 affects version 20.0.4.post2+tuxcare of gunicorn, and is fixed in 20.0.4.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.0.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.0.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6827 is fixed in version 20.0.4.post2+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-6827"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 is fixed in version 41.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 41.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 41.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 41.0.7.post3+tuxcare of cryptography."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 41.0.7.post3+tuxcare of cryptography. not_affected \u2014 python-cryptography version 41.0.7.post2+tuxcare is NOT AFFECTED by CVE-2026-69248. The vulnerability exists in the x509 verification module's DNS name constraint matching logic when validating wildcard SANs against intermediate CA constraints. However, the entire x509.verification module (including PolicyBuilder, Store, build_server_verifier, and the Rust cryptography-x509-verification compone...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 python-cryptography version 41.0.7.post2+tuxcare is NOT AFFECTED by CVE-2026-69248. The vulnerability exists in the x509 verification module's DNS name constraint matching logic when validating wildcard SANs against intermediate CA constraints. However, the entire x509.verification module (including PolicyBuilder, Store, build_server_verifier, and the Rust cryptography-x509-verification compone..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 does not affect version 41.0.7.post3+tuxcare of cryptography. not_affected \u2014 Version 41.0.7 is not affected by CVE-2026-69249. The vulnerable x509.verification module with its build_chain_inner function was introduced in cryptography version 42.0.0. Version 41.0.7 predates this feature and has no certificate chain validation API exposed to users. The INPUT type (certificate chains passed to PolicyBuilder.verify()) cannot be received in this version because the entire ve...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "impact_statement": "not_affected \u2014 Version 41.0.7 is not affected by CVE-2026-69249. The vulnerable x509.verification module with its build_chain_inner function was introduced in cryptography version 42.0.0. Version 41.0.7 predates this feature and has no certificate chain validation API exposed to users. The INPUT type (certificate chains passed to PolicyBuilder.verify()) cannot be received in this version because the entire ve..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 41.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 41.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-h4gh-qq45-vh27"
      },
      "action_statement": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 41.0.7.post3+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.32.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.32.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 affects version 2.32.3.post2+tuxcare of requests, and is fixed in 2.32.3.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      },
      "action_statement": "Vulnerability CVE-2024-47081 affects version 2.32.3.post2+tuxcare of requests, and is fixed in 2.32.3.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.32.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.32.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 is fixed in version 2.32.3.post2+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-32681 affects version 2.30.0.post1+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-32681"
      },
      "action_statement": "Vulnerability CVE-2023-32681 affects version 2.30.0.post1+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-35195 affects version 2.30.0.post1+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-35195"
      },
      "action_statement": "Vulnerability CVE-2024-35195 affects version 2.30.0.post1+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 affects version 2.30.0.post1+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      },
      "action_statement": "Vulnerability CVE-2024-47081 affects version 2.30.0.post1+tuxcare of requests, and is fixed in 2.30.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 affects version 2.30.0.post1+tuxcare of requests, and is fixed in 2.30.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      },
      "action_statement": "Vulnerability CVE-2026-25645 affects version 2.30.0.post1+tuxcare of requests, and is fixed in 2.30.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post5+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      },
      "action_statement": "Vulnerability CVE-2023-6940 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post5+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post5+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post5+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      },
      "action_statement": "Vulnerability CVE-2024-1594 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post5+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post5+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      },
      "action_statement": "Vulnerability CVE-2024-37054 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post5+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post5+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post5+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post5+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post5+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      },
      "action_statement": "Vulnerability CVE-2025-1474 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post5+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post5+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post5+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post5+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post5+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post5+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post5+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post5+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post5+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post5+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post5+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post5+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post5+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.9.1.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post5+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post5+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2021.10.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2021.10.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23491 is fixed in version 2021.10.8.post4+tuxcare of certifi.",
      "vulnerability": {
        "name": "CVE-2022-23491"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2021.10.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2021.10.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37920 is fixed in version 2021.10.8.post4+tuxcare of certifi.",
      "vulnerability": {
        "name": "CVE-2023-37920"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2021.10.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2021.10.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39689 is fixed in version 2021.10.8.post4+tuxcare of certifi.",
      "vulnerability": {
        "name": "CVE-2024-39689"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@60.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@60.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-40897 is fixed in version 60.0.0.post2+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2022-40897"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@60.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@60.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6345 is fixed in version 60.0.0.post2+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2024-6345"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@60.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@60.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 affects version 60.0.0.post2+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      },
      "action_statement": "Vulnerability CVE-2025-47273 affects version 60.0.0.post2+tuxcare of setuptools."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@60.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@60.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 affects version 60.0.0.post2+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      },
      "action_statement": "Vulnerability CVE-2026-59890 affects version 60.0.0.post2+tuxcare of setuptools."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29159 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-29159"
      },
      "action_statement": "Vulnerability CVE-2023-29159 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30798 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-30798"
      },
      "action_statement": "Vulnerability CVE-2023-30798 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      },
      "action_statement": "Vulnerability CVE-2024-24762 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      },
      "action_statement": "Vulnerability CVE-2024-47874 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.13.6.post1+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:22:44.885595+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.13.6.post1+tuxcare of starlette. starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0)."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      },
      "action_statement": "Vulnerability CVE-2026-48710 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      },
      "action_statement": "Vulnerability CVE-2026-48817 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      },
      "action_statement": "Vulnerability CVE-2026-48818 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      },
      "action_statement": "Vulnerability CVE-2026-54282 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      },
      "action_statement": "Vulnerability CVE-2026-54283 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-93gm-qmq6-w238 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-93gm-qmq6-w238"
      },
      "action_statement": "Vulnerability GHSA-93gm-qmq6-w238 affects version 0.13.6.post1+tuxcare of starlette, and is fixed in 0.13.6.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/websockets@8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/websockets@8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33880 is fixed in version 8.1.post1+tuxcare of websockets.",
      "vulnerability": {
        "name": "CVE-2021-33880"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 45.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 is fixed in version 45.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39892 is fixed in version 45.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-39892"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 affects version 45.0.7.post3+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      },
      "action_statement": "Vulnerability CVE-2026-69247 affects version 45.0.7.post3+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 is fixed in version 45.0.7.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 45.0.7.post3+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 45.0.7.post3+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 45.0.7.post3+tuxcare of cryptography. not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10318 is fixed in version 2.14.5.post3+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "AIKIDO-2026-10318"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64340 is fixed in version 2.14.5.post3+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "CVE-2025-64340"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27124 is fixed in version 2.14.5.post3+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "CVE-2026-27124"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32871 is fixed in version 2.14.5.post3+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "CVE-2026-32871"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/paramiko@3.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/paramiko@3.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-48795 is fixed in version 3.0.0.post2+tuxcare of paramiko.",
      "vulnerability": {
        "name": "CVE-2023-48795"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/paramiko@3.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/paramiko@3.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44405 is fixed in version 3.0.0.post2+tuxcare of paramiko.",
      "vulnerability": {
        "name": "CVE-2026-44405"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-65106 does not affect version 0.3.83.post2+tuxcare of langchain-core. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-65106"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26013 affects version 0.3.83.post2+tuxcare of langchain-core.",
      "vulnerability": {
        "name": "CVE-2026-26013"
      },
      "action_statement": "Vulnerability CVE-2026-26013 affects version 0.3.83.post2+tuxcare of langchain-core."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34070 is fixed in version 0.3.83.post2+tuxcare of langchain-core.",
      "vulnerability": {
        "name": "CVE-2026-34070"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44843 is fixed in version 0.3.83.post2+tuxcare of langchain-core.",
      "vulnerability": {
        "name": "CVE-2026-44843"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10085 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10410 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10410"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23934 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-23934"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-25577 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-25577"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46136 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-46136"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 is fixed in version 1.0.1.post6+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/flask@2.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@2.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-30861 affects version 2.2.1.post1+tuxcare of flask, and is fixed in 2.2.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-30861"
      },
      "action_statement": "Vulnerability CVE-2023-30861 affects version 2.2.1.post1+tuxcare of flask, and is fixed in 2.2.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/flask@2.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@2.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27205 affects version 2.2.1.post1+tuxcare of flask, and is fixed in 2.2.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27205"
      },
      "action_statement": "Vulnerability CVE-2026-27205 affects version 2.2.1.post1+tuxcare of flask, and is fixed in 2.2.1.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 43.0.1.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 is fixed in version 43.0.1.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 43.0.1.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 43.0.1.post3+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 43.0.1.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.1.post3+tuxcare of cryptography, and is fixed in 43.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.1.post3+tuxcare of cryptography, and is fixed in 43.0.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mysql-connector-python@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mysql-connector-python@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21272 is fixed in version 8.4.0.post1+tuxcare of mysql-connector-python.",
      "vulnerability": {
        "name": "CVE-2024-21272"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@59.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@59.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-40897 is fixed in version 59.8.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2022-40897"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@59.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@59.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6345 affects version 59.8.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2024-6345"
      },
      "action_statement": "Vulnerability CVE-2024-6345 affects version 59.8.0.post1+tuxcare of setuptools."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@59.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@59.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 affects version 59.8.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      },
      "action_statement": "Vulnerability CVE-2025-47273 affects version 59.8.0.post1+tuxcare of setuptools."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@59.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@59.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 affects version 59.8.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      },
      "action_statement": "Vulnerability CVE-2026-59890 affects version 59.8.0.post1+tuxcare of setuptools."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29159 is fixed in version 0.25.0.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2023-29159"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.25.0.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.25.0.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.25.0.post2+tuxcare of starlette. CVE-2025-62727 is a Range header parsing flaw in FileResponse. That parsing was introduced upstream in starlette 0.39.0; version 0.25.0 predates it. Verified on tuxcare-current/0.25.0: the string \"Range\" does not occur anywhere in the starlette package, and FileResponse implements no range handling. Same disposition and same reasoning as starlette 0.27.0 (VPV 81209), which is already not_affected with justification code_not_present.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "CVE-2025-62727 is a Range header parsing flaw in FileResponse. That parsing was introduced upstream in starlette 0.39.0; version 0.25.0 predates it. Verified on tuxcare-current/0.25.0: the string \"Range\" does not occur anywhere in the starlette package, and FileResponse implements no range handling. Same disposition and same reasoning as starlette 0.27.0 (VPV 81209), which is already not_affected with justification code_not_present."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 is fixed in version 0.25.0.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 is fixed in version 0.25.0.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 is fixed in version 0.25.0.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 is fixed in version 0.25.0.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 is fixed in version 0.25.0.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 45.0.7.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 45.0.7.post2+tuxcare of cryptography, and is fixed in 45.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 45.0.7.post2+tuxcare of cryptography, and is fixed in 45.0.7.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39892 is fixed in version 45.0.7.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-39892"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 affects version 45.0.7.post2+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      },
      "action_statement": "Vulnerability CVE-2026-69247 affects version 45.0.7.post2+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 45.0.7.post2+tuxcare of cryptography, and is fixed in 45.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 45.0.7.post2+tuxcare of cryptography, and is fixed in 45.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 45.0.7.post2+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 45.0.7.post2+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 45.0.7.post2+tuxcare of cryptography. not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-0286 affects version 3.4.8.post3+tuxcare of cryptography, and is fixed in 3.4.8.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-0286"
      },
      "action_statement": "Vulnerability CVE-2023-0286 affects version 3.4.8.post3+tuxcare of cryptography, and is fixed in 3.4.8.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-23931"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-3446 is fixed in version 3.4.8.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-3446"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49083 affects version 3.4.8.post3+tuxcare of cryptography, and is fixed in 3.4.8.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49083"
      },
      "action_statement": "Vulnerability CVE-2023-49083 affects version 3.4.8.post3+tuxcare of cryptography, and is fixed in 3.4.8.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-50782"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 affects version 3.4.8.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      },
      "action_statement": "Vulnerability CVE-2024-0727 affects version 3.4.8.post3+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12797 is fixed in version 3.4.8.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-12797"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 3.4.8.post3+tuxcare of cryptography, and is fixed in 3.4.8.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 3.4.8.post3+tuxcare of cryptography, and is fixed in 3.4.8.post6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 does not affect version 3.4.8.post3+tuxcare of cryptography. Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "impact_statement": "Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 3.4.8.post3+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 does not affect version 3.4.8.post3+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post3+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons...",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5cpq-8wj7-hf2v does not affect version 3.4.8.post3+tuxcare of cryptography. cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5cpq-8wj7-hf2v"
      },
      "impact_statement": "cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-jm77-qphf-c4w8"
      },
      "action_statement": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post3+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-v8gr-m533-ghj9"
      },
      "action_statement": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post3+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2023.7.22.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2023.7.22.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39689 is fixed in version 2023.7.22.post2+tuxcare of certifi.",
      "vulnerability": {
        "name": "CVE-2024-39689"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64439 is fixed in version 2.1.2.post2+tuxcare of langgraph-checkpoint.",
      "vulnerability": {
        "name": "CVE-2025-64439"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27794 is fixed in version 2.1.2.post2+tuxcare of langgraph-checkpoint.",
      "vulnerability": {
        "name": "CVE-2026-27794"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48775 affects version 2.1.2.post2+tuxcare of langgraph-checkpoint, and is fixed in 2.1.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48775"
      },
      "action_statement": "Vulnerability CVE-2026-48775 affects version 2.1.2.post2+tuxcare of langgraph-checkpoint, and is fixed in 2.1.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2021.10.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2021.10.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23491 affects version 2021.10.8.post1+tuxcare of certifi, and is fixed in 2021.10.8.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-23491"
      },
      "action_statement": "Vulnerability CVE-2022-23491 affects version 2021.10.8.post1+tuxcare of certifi, and is fixed in 2021.10.8.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2021.10.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2021.10.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37920 affects version 2021.10.8.post1+tuxcare of certifi, and is fixed in 2021.10.8.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-37920"
      },
      "action_statement": "Vulnerability CVE-2023-37920 affects version 2021.10.8.post1+tuxcare of certifi, and is fixed in 2021.10.8.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2021.10.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2021.10.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39689 affects version 2021.10.8.post1+tuxcare of certifi, and is fixed in 2021.10.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39689"
      },
      "action_statement": "Vulnerability CVE-2024-39689 affects version 2021.10.8.post1+tuxcare of certifi, and is fixed in 2021.10.8.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      },
      "action_statement": "Vulnerability CVE-2023-6709 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      },
      "action_statement": "Vulnerability CVE-2023-6753 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post1+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      },
      "action_statement": "Vulnerability CVE-2023-6909 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      },
      "action_statement": "Vulnerability CVE-2023-6940 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      },
      "action_statement": "Vulnerability CVE-2023-6974 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      },
      "action_statement": "Vulnerability CVE-2023-6975 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post1+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      },
      "action_statement": "Vulnerability CVE-2024-1483 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post1+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post1+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      },
      "action_statement": "Vulnerability CVE-2024-1593 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      },
      "action_statement": "Vulnerability CVE-2024-1594 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      },
      "action_statement": "Vulnerability CVE-2024-27132 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      },
      "action_statement": "Vulnerability CVE-2024-27133 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      },
      "action_statement": "Vulnerability CVE-2024-27134 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      },
      "action_statement": "Vulnerability CVE-2024-2928 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post1+tuxcare of mlflow."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      },
      "action_statement": "Vulnerability CVE-2024-3573 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post1+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      },
      "action_statement": "Vulnerability CVE-2024-37053 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      },
      "action_statement": "Vulnerability CVE-2024-37054 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      },
      "action_statement": "Vulnerability CVE-2024-37055 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      },
      "action_statement": "Vulnerability CVE-2024-37056 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post1+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      },
      "action_statement": "Vulnerability CVE-2024-37058 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post1+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post1+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post1+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      },
      "action_statement": "Vulnerability CVE-2024-4263 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      },
      "action_statement": "Vulnerability CVE-2024-6838 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      },
      "action_statement": "Vulnerability CVE-2024-8859 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post1+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      },
      "action_statement": "Vulnerability CVE-2025-11200 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      },
      "action_statement": "Vulnerability CVE-2025-11201 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      },
      "action_statement": "Vulnerability CVE-2025-1474 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post1+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post1+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post1+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post1+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      },
      "action_statement": "Vulnerability CVE-2025-52967 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post1+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      },
      "action_statement": "Vulnerability CVE-2026-0596 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post1+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post1+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post1+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post1+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post1+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post1+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post1+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post1+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      },
      "action_statement": "Vulnerability CVE-2026-4137 affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post1+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post1+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10318 is fixed in version 2.14.5.post2+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "AIKIDO-2026-10318"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64340 affects version 2.14.5.post2+tuxcare of fastmcp, and is fixed in 2.14.5.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64340"
      },
      "action_statement": "Vulnerability CVE-2025-64340 affects version 2.14.5.post2+tuxcare of fastmcp, and is fixed in 2.14.5.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27124 affects version 2.14.5.post2+tuxcare of fastmcp, and is fixed in 2.14.5.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27124"
      },
      "action_statement": "Vulnerability CVE-2026-27124 affects version 2.14.5.post2+tuxcare of fastmcp, and is fixed in 2.14.5.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32871 is fixed in version 2.14.5.post2+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "CVE-2026-32871"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.31.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.31.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-35195 affects version 2.31.0.post2+tuxcare of requests, and is fixed in 2.31.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-35195"
      },
      "action_statement": "Vulnerability CVE-2024-35195 affects version 2.31.0.post2+tuxcare of requests, and is fixed in 2.31.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.31.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.31.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 affects version 2.31.0.post2+tuxcare of requests, and is fixed in 2.31.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      },
      "action_statement": "Vulnerability CVE-2024-47081 affects version 2.31.0.post2+tuxcare of requests, and is fixed in 2.31.0.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.31.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.31.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 is fixed in version 2.31.0.post2+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post12+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post12+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post12+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post12+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post12+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post12+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post12+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post12+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.5.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post12+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10216 is fixed in version 20.1.0.post1+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "AIKIDO-2024-10216"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10742 affects version 20.1.0.post1+tuxcare of gunicorn, and is fixed in 20.1.0.post3+tuxcare.",
      "vulnerability": {
        "name": "AIKIDO-2026-10742"
      },
      "action_statement": "Vulnerability AIKIDO-2026-10742 affects version 20.1.0.post1+tuxcare of gunicorn, and is fixed in 20.1.0.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1135 is fixed in version 20.1.0.post1+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-1135"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6827 is fixed in version 20.1.0.post1+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-6827"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-7923 affects version 20.1.0.post1+tuxcare of gunicorn, and is fixed in 20.1.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-7923"
      },
      "action_statement": "Vulnerability CVE-2024-7923 affects version 20.1.0.post1+tuxcare of gunicorn, and is fixed in 20.1.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post17+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post17+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post17+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post17+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post17+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post17+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post17+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post17+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post17+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post17+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post17+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post17+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.5.post17+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-jose@3.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-jose@3.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-33663 affects version 3.3.0.post1+tuxcare of python-jose, and is fixed in 3.3.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-33663"
      },
      "action_statement": "Vulnerability CVE-2024-33663 affects version 3.3.0.post1+tuxcare of python-jose, and is fixed in 3.3.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-jose@3.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-jose@3.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-33664 is fixed in version 3.3.0.post1+tuxcare of python-jose.",
      "vulnerability": {
        "name": "CVE-2024-33664"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-2148 affects version 1.13.1.post2+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-2148"
      },
      "action_statement": "Vulnerability CVE-2025-2148 affects version 1.13.1.post2+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-2149 affects version 1.13.1.post2+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-2149"
      },
      "action_statement": "Vulnerability CVE-2025-2149 affects version 1.13.1.post2+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-2953 affects version 1.13.1.post2+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-2953"
      },
      "action_statement": "Vulnerability CVE-2025-2953 affects version 1.13.1.post2+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-2998 affects version 1.13.1.post2+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-2998"
      },
      "action_statement": "Vulnerability CVE-2025-2998 affects version 1.13.1.post2+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-2999 affects version 1.13.1.post2+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-2999"
      },
      "action_statement": "Vulnerability CVE-2025-2999 affects version 1.13.1.post2+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3000 affects version 1.13.1.post2+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-3000"
      },
      "action_statement": "Vulnerability CVE-2025-3000 affects version 1.13.1.post2+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3001 affects version 1.13.1.post2+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-3001"
      },
      "action_statement": "Vulnerability CVE-2025-3001 affects version 1.13.1.post2+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3730 affects version 1.13.1.post2+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-3730"
      },
      "action_statement": "Vulnerability CVE-2025-3730 affects version 1.13.1.post2+tuxcare of torch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post10+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post10+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post10+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post10+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post10+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post10+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 affects version 2.9.1.post10+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      },
      "action_statement": "Vulnerability CVE-2024-37054 affects version 2.9.1.post10+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post10+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post10+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post10+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post10+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post10+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post10+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post10+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post10+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post10+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post10+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post10+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post10+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post10+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post10+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post10+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post10+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post10+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post10+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post10+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm is fixed in version 2.9.1.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.63.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.63.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-32677 is fixed in version 0.63.0.post4+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2021-32677"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.63.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.63.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.63.0.post4+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post9+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post9+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post9+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post9+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post9+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post9+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post9+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post9+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@23.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@23.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10742 is fixed in version 23.0.0.post1+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "AIKIDO-2026-10742"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post7+tuxcare of mlflow-skinny. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post7+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post7+tuxcare of mlflow-skinny. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post7+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post7+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post7+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post7+tuxcare of mlflow-skinny."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post7+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post7+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post7+tuxcare of mlflow-skinny."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post7+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post7+tuxcare of mlflow-skinny. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post7+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post7+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post7+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post7+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post7+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post7+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post7+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post2+tuxcare of mlflow-skinny. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post2+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post2+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post2+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post2+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post2+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post2+tuxcare of mlflow-skinny. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post2+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      },
      "action_statement": "Vulnerability CVE-2026-0596 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post2+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post2+tuxcare of mlflow-skinny."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post2+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post2+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "action_statement": "Vulnerability CVE-2026-2614 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post2+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post2+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post2+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post2+tuxcare of mlflow-skinny."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post2+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post2+tuxcare of mlflow-skinny. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post2+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      },
      "action_statement": "Vulnerability CVE-2026-4137 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post2+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post2+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10318 is fixed in version 2.14.5.post1+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "AIKIDO-2026-10318"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64340 affects version 2.14.5.post1+tuxcare of fastmcp, and is fixed in 2.14.5.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64340"
      },
      "action_statement": "Vulnerability CVE-2025-64340 affects version 2.14.5.post1+tuxcare of fastmcp, and is fixed in 2.14.5.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27124 affects version 2.14.5.post1+tuxcare of fastmcp, and is fixed in 2.14.5.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27124"
      },
      "action_statement": "Vulnerability CVE-2026-27124 affects version 2.14.5.post1+tuxcare of fastmcp, and is fixed in 2.14.5.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32871 affects version 2.14.5.post1+tuxcare of fastmcp, and is fixed in 2.14.5.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32871"
      },
      "action_statement": "Vulnerability CVE-2026-32871 affects version 2.14.5.post1+tuxcare of fastmcp, and is fixed in 2.14.5.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post15+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post15+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post15+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post15+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post15+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post15+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post15+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post15+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post15+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post15+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post15+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post15+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post15+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post15+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post15+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post15+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.5.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post3+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      },
      "action_statement": "Vulnerability CVE-2023-6940 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post3+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      },
      "action_statement": "Vulnerability CVE-2024-1483 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post3+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post3+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      },
      "action_statement": "Vulnerability CVE-2024-1594 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post3+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post3+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      },
      "action_statement": "Vulnerability CVE-2024-37053 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      },
      "action_statement": "Vulnerability CVE-2024-37054 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      },
      "action_statement": "Vulnerability CVE-2024-37055 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post3+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      },
      "action_statement": "Vulnerability CVE-2024-37058 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post3+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post3+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post3+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      },
      "action_statement": "Vulnerability CVE-2024-4263 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      },
      "action_statement": "Vulnerability CVE-2024-6838 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      },
      "action_statement": "Vulnerability CVE-2024-8859 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post3+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      },
      "action_statement": "Vulnerability CVE-2025-1474 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post3+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post3+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post3+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post3+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post3+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      },
      "action_statement": "Vulnerability CVE-2026-0596 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post3+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post3+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post3+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post3+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post3+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post3+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post3+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post3+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      },
      "action_statement": "Vulnerability CVE-2026-4137 affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post3+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post3+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-0286 is fixed in version 3.4.8.post6+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-0286"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post6+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-23931"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-3446 is fixed in version 3.4.8.post6+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-3446"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49083 is fixed in version 3.4.8.post6+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-49083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post6+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-50782"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 affects version 3.4.8.post6+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      },
      "action_statement": "Vulnerability CVE-2024-0727 affects version 3.4.8.post6+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12797 is fixed in version 3.4.8.post6+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-12797"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 3.4.8.post6+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 does not affect version 3.4.8.post6+tuxcare of cryptography. Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "impact_statement": "Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 3.4.8.post6+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 does not affect version 3.4.8.post6+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post6+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons...",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5cpq-8wj7-hf2v does not affect version 3.4.8.post6+tuxcare of cryptography. cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5cpq-8wj7-hf2v"
      },
      "impact_statement": "cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post6+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-jm77-qphf-c4w8"
      },
      "action_statement": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post6+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post6+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-v8gr-m533-ghj9"
      },
      "action_statement": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post6+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33430 affects version 1.15.4.post1+tuxcare of numpy, and is fixed in 1.15.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-33430"
      },
      "action_statement": "Vulnerability CVE-2021-33430 affects version 1.15.4.post1+tuxcare of numpy, and is fixed in 1.15.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41495 affects version 1.15.4.post1+tuxcare of numpy, and is fixed in 1.15.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-41495"
      },
      "action_statement": "Vulnerability CVE-2021-41495 affects version 1.15.4.post1+tuxcare of numpy, and is fixed in 1.15.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41496 affects version 1.15.4.post1+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-41496"
      },
      "action_statement": "Vulnerability CVE-2021-41496 affects version 1.15.4.post1+tuxcare of numpy."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10085 is fixed in version 2.2.3.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10410 is fixed in version 2.2.3.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10410"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46136 is fixed in version 2.2.3.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-46136"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 affects version 2.2.3.post4+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      },
      "action_statement": "Vulnerability CVE-2024-34069 affects version 2.2.3.post4+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 is fixed in version 2.2.3.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 is fixed in version 2.2.3.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 affects version 2.2.3.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      },
      "action_statement": "Vulnerability CVE-2025-66221 affects version 2.2.3.post4+tuxcare of werkzeug."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 affects version 2.2.3.post4+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      },
      "action_statement": "Vulnerability CVE-2026-21860 affects version 2.2.3.post4+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 affects version 2.2.3.post4+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      },
      "action_statement": "Vulnerability CVE-2026-27199 affects version 2.2.3.post4+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@68.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@68.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6345 is fixed in version 68.0.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2024-6345"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@68.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@68.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 is fixed in version 68.0.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@68.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@68.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 affects version 68.0.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      },
      "action_statement": "Vulnerability CVE-2026-59890 affects version 68.0.0.post1+tuxcare of setuptools."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post5+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post5+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post5+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post5+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post5+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post5+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post5+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post5+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6839 affects version 4.0.2.post2+tuxcare of flask-cors, and is fixed in 4.0.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-6839"
      },
      "action_statement": "Vulnerability CVE-2024-6839 affects version 4.0.2.post2+tuxcare of flask-cors, and is fixed in 4.0.2.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6844 is fixed in version 4.0.2.post2+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6844"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6866 is fixed in version 4.0.2.post2+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6866"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33430 affects version 1.15.4.post3+tuxcare of numpy, and is fixed in 1.15.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-33430"
      },
      "action_statement": "Vulnerability CVE-2021-33430 affects version 1.15.4.post3+tuxcare of numpy, and is fixed in 1.15.4.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41495 is fixed in version 1.15.4.post3+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-41495"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41496 affects version 1.15.4.post3+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-41496"
      },
      "action_statement": "Vulnerability CVE-2021-41496 affects version 1.15.4.post3+tuxcare of numpy."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-32681 affects version 2.25.1.post2+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-32681"
      },
      "action_statement": "Vulnerability CVE-2023-32681 affects version 2.25.1.post2+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-35195 affects version 2.25.1.post2+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-35195"
      },
      "action_statement": "Vulnerability CVE-2024-35195 affects version 2.25.1.post2+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 affects version 2.25.1.post2+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      },
      "action_statement": "Vulnerability CVE-2024-47081 affects version 2.25.1.post2+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 is fixed in version 2.25.1.post2+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/orjson@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/orjson@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27454 is fixed in version 3.8.5.post3+tuxcare of orjson.",
      "vulnerability": {
        "name": "CVE-2024-27454"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/orjson@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/orjson@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67221 is fixed in version 3.8.5.post3+tuxcare of orjson.",
      "vulnerability": {
        "name": "CVE-2025-67221"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 42.0.8.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 42.0.8.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 42.0.8.post2+tuxcare of cryptography."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 42.0.8.post2+tuxcare of cryptography. not_affected \u2014 Target version 42.0.8.post2+tuxcare is NOT affected by CVE-2026-69248. The vulnerability requires wildcard DNS SAN support in name constraint validation, which was introduced in upstream commit 286c89128 (Jan 7, 2025) and fixed in commit 91d728897 (Mar 25, 2026, also known as CVE-2026-34073). The 42.x branch never received the vulnerable wildcard support code. Instead, this version uses the old...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 Target version 42.0.8.post2+tuxcare is NOT affected by CVE-2026-69248. The vulnerability requires wildcard DNS SAN support in name constraint validation, which was introduced in upstream commit 286c89128 (Jan 7, 2025) and fixed in commit 91d728897 (Mar 25, 2026, also known as CVE-2026-34073). The 42.x branch never received the vulnerable wildcard support code. Instead, this version uses the old..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 42.0.8.post2+tuxcare of cryptography, and is fixed in 42.0.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 42.0.8.post2+tuxcare of cryptography, and is fixed in 42.0.8.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 42.0.8.post2+tuxcare of cryptography, and is fixed in 42.0.8.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 42.0.8.post2+tuxcare of cryptography, and is fixed in 42.0.8.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post6+tuxcare of mlflow-skinny. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post6+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post6+tuxcare of mlflow-skinny. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post6+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post6+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post6+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post6+tuxcare of mlflow-skinny."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post6+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post6+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post6+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post6+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post6+tuxcare of mlflow-skinny."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post6+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post6+tuxcare of mlflow-skinny. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post6+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post6+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post6+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post6+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post6+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post6+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post6+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 43.0.1.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 is fixed in version 43.0.1.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 43.0.1.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 43.0.1.post4+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 43.0.1.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 43.0.1.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 affects version 0.27.0.post6+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      },
      "action_statement": "Vulnerability CVE-2024-24762 affects version 0.27.0.post6+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post6+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 is fixed in version 0.27.0.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 is fixed in version 0.27.0.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 is fixed in version 0.27.0.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 is fixed in version 0.27.0.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.31.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.31.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-35195 affects version 2.31.0.post1+tuxcare of requests, and is fixed in 2.31.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-35195"
      },
      "action_statement": "Vulnerability CVE-2024-35195 affects version 2.31.0.post1+tuxcare of requests, and is fixed in 2.31.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.31.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.31.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 affects version 2.31.0.post1+tuxcare of requests, and is fixed in 2.31.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      },
      "action_statement": "Vulnerability CVE-2024-47081 affects version 2.31.0.post1+tuxcare of requests, and is fixed in 2.31.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.31.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.31.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 affects version 2.31.0.post1+tuxcare of requests, and is fixed in 2.31.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      },
      "action_statement": "Vulnerability CVE-2026-25645 affects version 2.31.0.post1+tuxcare of requests, and is fixed in 2.31.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10216 is fixed in version 20.1.0.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "AIKIDO-2024-10216"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10742 is fixed in version 20.1.0.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "AIKIDO-2026-10742"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1135 is fixed in version 20.1.0.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-1135"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6827 is fixed in version 20.1.0.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-6827"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-7923 is fixed in version 20.1.0.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-7923"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@3.0.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@3.0.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1681 is fixed in version 3.0.10.post1+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-1681"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@3.0.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@3.0.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6221 does not affect version 3.0.10.post1+tuxcare of flask-cors. flask-cors 3.0.10 never sets Access-Control-Allow-Private-Network. The header was introduced upstream in 24070be on 2022-06-15, after 3.0.10 (May 2021), and that commit is not an ancestor of tuxcare-current/3.0.10; grep for private_network in flask_cors/ is empty. Verified by execution: a preflight carrying Access-Control-Request-Private-Network: true returns only Access-Control-Allow-Origin and Access-Control-Allow-Methods. The upstream fix 7ae310c only makes that existing header configurable, so there is nothing to backport. PYELS-158.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-6221"
      },
      "impact_statement": "flask-cors 3.0.10 never sets Access-Control-Allow-Private-Network. The header was introduced upstream in 24070be on 2022-06-15, after 3.0.10 (May 2021), and that commit is not an ancestor of tuxcare-current/3.0.10; grep for private_network in flask_cors/ is empty. Verified by execution: a preflight carrying Access-Control-Request-Private-Network: true returns only Access-Control-Allow-Origin and Access-Control-Allow-Methods. The upstream fix 7ae310c only makes that existing header configurable, so there is nothing to backport. PYELS-158."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@3.0.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@3.0.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6839 is fixed in version 3.0.10.post1+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6839"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@3.0.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@3.0.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6844 is fixed in version 3.0.10.post1+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6844"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@3.0.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@3.0.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6866 is fixed in version 3.0.10.post1+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6866"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dnspython@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dnspython@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29483 affects version 2.3.0.post1+tuxcare of dnspython, and is fixed in 2.3.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-29483"
      },
      "action_statement": "Vulnerability CVE-2023-29483 affects version 2.3.0.post1+tuxcare of dnspython, and is fixed in 2.3.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 is fixed in version 75.8.0.post2+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 is fixed in version 75.8.0.post2+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post1+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53981 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53981"
      },
      "action_statement": "Vulnerability CVE-2024-53981 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24486 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24486"
      },
      "action_statement": "Vulnerability CVE-2026-24486 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40347 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-40347"
      },
      "action_statement": "Vulnerability CVE-2026-40347 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42561 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42561"
      },
      "action_statement": "Vulnerability CVE-2026-42561 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53537 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53537"
      },
      "action_statement": "Vulnerability CVE-2026-53537 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53538 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53538"
      },
      "action_statement": "Vulnerability CVE-2026-53538 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53540 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53540"
      },
      "action_statement": "Vulnerability CVE-2026-53540 affects version 0.0.6.post1+tuxcare of python-multipart, and is fixed in 0.0.6.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48379 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2025-48379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 11.2.1.post6+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 11.2.1.post6+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 11.2.1.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 is fixed in version 41.0.7.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 41.0.7.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 41.0.7.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 41.0.7.post2+tuxcare of cryptography."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 41.0.7.post2+tuxcare of cryptography. not_affected \u2014 python-cryptography version 41.0.7.post2+tuxcare is NOT AFFECTED by CVE-2026-69248. The vulnerability exists in the x509 verification module's DNS name constraint matching logic when validating wildcard SANs against intermediate CA constraints. However, the entire x509.verification module (including PolicyBuilder, Store, build_server_verifier, and the Rust cryptography-x509-verification compone...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 python-cryptography version 41.0.7.post2+tuxcare is NOT AFFECTED by CVE-2026-69248. The vulnerability exists in the x509 verification module's DNS name constraint matching logic when validating wildcard SANs against intermediate CA constraints. However, the entire x509.verification module (including PolicyBuilder, Store, build_server_verifier, and the Rust cryptography-x509-verification compone..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 does not affect version 41.0.7.post2+tuxcare of cryptography. not_affected \u2014 Version 41.0.7 is not affected by CVE-2026-69249. The vulnerable x509.verification module with its build_chain_inner function was introduced in cryptography version 42.0.0. Version 41.0.7 predates this feature and has no certificate chain validation API exposed to users. The INPUT type (certificate chains passed to PolicyBuilder.verify()) cannot be received in this version because the entire ve...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "impact_statement": "not_affected \u2014 Version 41.0.7 is not affected by CVE-2026-69249. The vulnerable x509.verification module with its build_chain_inner function was introduced in cryptography version 42.0.0. Version 41.0.7 predates this feature and has no certificate chain validation API exposed to users. The INPUT type (certificate chains passed to PolicyBuilder.verify()) cannot be received in this version because the entire ve..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 41.0.7.post2+tuxcare of cryptography, and is fixed in 41.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 41.0.7.post2+tuxcare of cryptography, and is fixed in 41.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 41.0.7.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-h4gh-qq45-vh27"
      },
      "action_statement": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 41.0.7.post2+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 affects version 2.3.8.post1+tuxcare of werkzeug, and is fixed in 2.3.8.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      },
      "action_statement": "Vulnerability CVE-2024-34069 affects version 2.3.8.post1+tuxcare of werkzeug, and is fixed in 2.3.8.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 affects version 2.3.8.post1+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      },
      "action_statement": "Vulnerability CVE-2024-49766 affects version 2.3.8.post1+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 affects version 2.3.8.post1+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      },
      "action_statement": "Vulnerability CVE-2024-49767 affects version 2.3.8.post1+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 is fixed in version 2.3.8.post1+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 affects version 2.3.8.post1+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      },
      "action_statement": "Vulnerability CVE-2026-21860 affects version 2.3.8.post1+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 affects version 2.3.8.post1+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      },
      "action_statement": "Vulnerability CVE-2026-27199 affects version 2.3.8.post1+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/idna@2.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/idna@2.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3651 is fixed in version 2.8.post1+tuxcare of idna.",
      "vulnerability": {
        "name": "CVE-2024-3651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/idna@2.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/idna@2.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45409 affects version 2.8.post1+tuxcare of idna.",
      "vulnerability": {
        "name": "CVE-2026-45409"
      },
      "action_statement": "Vulnerability CVE-2026-45409 affects version 2.8.post1+tuxcare of idna."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post2+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post2+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-53981"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24486 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24486"
      },
      "action_statement": "Vulnerability CVE-2026-24486 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40347 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-40347"
      },
      "action_statement": "Vulnerability CVE-2026-40347 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42561 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42561"
      },
      "action_statement": "Vulnerability CVE-2026-42561 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53537 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53537"
      },
      "action_statement": "Vulnerability CVE-2026-53537 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53538 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53538"
      },
      "action_statement": "Vulnerability CVE-2026-53538 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53540 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53540"
      },
      "action_statement": "Vulnerability CVE-2026-53540 affects version 0.0.6.post2+tuxcare of python-multipart, and is fixed in 0.0.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 43.0.1.post1+tuxcare of cryptography, and is fixed in 43.0.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 43.0.1.post1+tuxcare of cryptography, and is fixed in 43.0.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 43.0.1.post1+tuxcare of cryptography, and is fixed in 43.0.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 43.0.1.post1+tuxcare of cryptography, and is fixed in 43.0.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 43.0.1.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 43.0.1.post1+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 43.0.1.post1+tuxcare of cryptography, and is fixed in 43.0.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 43.0.1.post1+tuxcare of cryptography, and is fixed in 43.0.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.1.post1+tuxcare of cryptography, and is fixed in 43.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.1.post1+tuxcare of cryptography, and is fixed in 43.0.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyarrow@12.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyarrow@12.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47248 is fixed in version 12.0.1.post1+tuxcare of pyarrow.",
      "vulnerability": {
        "name": "CVE-2023-47248"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 affects version 42.0.0.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      },
      "action_statement": "Vulnerability CVE-2024-0727 affects version 42.0.0.post1+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-28T09:32:48.362925+00:00",
      "status_notes": "Vulnerability CVE-2024-12797 is fixed in version 42.0.0.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-12797"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 42.0.0.post1+tuxcare of cryptography, and is fixed in 42.0.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 42.0.0.post1+tuxcare of cryptography, and is fixed in 42.0.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 42.0.0.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 42.0.0.post1+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 42.0.0.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 42.0.0.post1+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 42.0.0.post1+tuxcare of cryptography, and is fixed in 42.0.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 42.0.0.post1+tuxcare of cryptography, and is fixed in 42.0.0.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 42.0.0.post1+tuxcare of cryptography. not_affected \u2014 The target repository (cryptography 42.0.0.post1+tuxcare source code) is not affected by GHSA-537c-gmf6-5ccf. This CVE concerns vulnerable OpenSSL bundled in pre-built PyPI wheels, not the cryptography source code itself. The CVE explicitly excludes source builds from its scope, stating that sdist users are responsible for their own OpenSSL. The target is a source repository with no vendored Op...",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The target repository (cryptography 42.0.0.post1+tuxcare source code) is not affected by GHSA-537c-gmf6-5ccf. This CVE concerns vulnerable OpenSSL bundled in pre-built PyPI wheels, not the cryptography source code itself. The CVE explicitly excludes source builds from its scope, stating that sdist users are responsible for their own OpenSSL. The target is a source repository with no vendored Op..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 42.0.0.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-h4gh-qq45-vh27"
      },
      "action_statement": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 42.0.0.post1+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33430 affects version 1.15.4.post2+tuxcare of numpy, and is fixed in 1.15.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-33430"
      },
      "action_statement": "Vulnerability CVE-2021-33430 affects version 1.15.4.post2+tuxcare of numpy, and is fixed in 1.15.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41495 affects version 1.15.4.post2+tuxcare of numpy, and is fixed in 1.15.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-41495"
      },
      "action_statement": "Vulnerability CVE-2021-41495 affects version 1.15.4.post2+tuxcare of numpy, and is fixed in 1.15.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41496 affects version 1.15.4.post2+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-41496"
      },
      "action_statement": "Vulnerability CVE-2021-41496 affects version 1.15.4.post2+tuxcare of numpy."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33430 affects version 1.16.0.post2+tuxcare of numpy, and is fixed in 1.16.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-33430"
      },
      "action_statement": "Vulnerability CVE-2021-33430 affects version 1.16.0.post2+tuxcare of numpy, and is fixed in 1.16.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-34141 affects version 1.16.0.post2+tuxcare of numpy, and is fixed in 1.16.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-34141"
      },
      "action_statement": "Vulnerability CVE-2021-34141 affects version 1.16.0.post2+tuxcare of numpy, and is fixed in 1.16.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41495 affects version 1.16.0.post2+tuxcare of numpy, and is fixed in 1.16.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-41495"
      },
      "action_statement": "Vulnerability CVE-2021-41495 affects version 1.16.0.post2+tuxcare of numpy, and is fixed in 1.16.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      },
      "action_statement": "Vulnerability CVE-2024-24762 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post2+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      },
      "action_statement": "Vulnerability CVE-2026-48710 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      },
      "action_statement": "Vulnerability CVE-2026-48817 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      },
      "action_statement": "Vulnerability CVE-2026-48818 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      },
      "action_statement": "Vulnerability CVE-2026-54282 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      },
      "action_statement": "Vulnerability CVE-2026-54283 affects version 0.27.0.post2+tuxcare of starlette, and is fixed in 0.27.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48379 is fixed in version 11.2.1.post1+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2025-48379"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      },
      "action_statement": "Vulnerability CVE-2026-25990 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      },
      "action_statement": "Vulnerability CVE-2026-40192 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      },
      "action_statement": "Vulnerability CVE-2026-42309 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 11.2.1.post1+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post7+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 affects version 2.9.1.post7+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      },
      "action_statement": "Vulnerability CVE-2023-6940 affects version 2.9.1.post7+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post7+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post7+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post7+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post7+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post7+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 affects version 2.9.1.post7+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      },
      "action_statement": "Vulnerability CVE-2024-37054 affects version 2.9.1.post7+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post7+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post7+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post7+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post7+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post7+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post7+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post7+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post7+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post7+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post7+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post7+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post7+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post7+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.9.1.post7+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.9.1.post7+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post7+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post7+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post7+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post7+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post7+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.9.1.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post7+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post7+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post7+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33430 affects version 1.16.0.post3+tuxcare of numpy, and is fixed in 1.16.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-33430"
      },
      "action_statement": "Vulnerability CVE-2021-33430 affects version 1.16.0.post3+tuxcare of numpy, and is fixed in 1.16.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-34141 is fixed in version 1.16.0.post3+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-34141"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41495 is fixed in version 1.16.0.post3+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-41495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pydantic@1.10.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pydantic@1.10.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3772 is fixed in version 1.10.0.post1+tuxcare of pydantic.",
      "vulnerability": {
        "name": "CVE-2024-3772"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10216 is fixed in version 21.2.0.post2+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "AIKIDO-2024-10216"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1135 is fixed in version 21.2.0.post2+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-1135"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6827 is fixed in version 21.2.0.post2+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-6827"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-7923 affects version 21.2.0.post2+tuxcare of gunicorn, and is fixed in 21.2.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-7923"
      },
      "action_statement": "Vulnerability CVE-2024-7923 affects version 21.2.0.post2+tuxcare of gunicorn, and is fixed in 21.2.0.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post2+tuxcare of mlflow. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post2+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post2+tuxcare of mlflow. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post2+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      },
      "action_statement": "Vulnerability CVE-2026-0596 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post2+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post2+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "action_statement": "Vulnerability CVE-2026-2614 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post2+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post2+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post2+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post2+tuxcare of mlflow. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post2+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      },
      "action_statement": "Vulnerability CVE-2026-4137 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post2+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post2+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 43.0.3.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 is fixed in version 43.0.3.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 43.0.3.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 43.0.3.post5+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 43.0.3.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 43.0.3.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/anyio@3.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/anyio@3.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10170 is fixed in version 3.7.1.post1+tuxcare of anyio.",
      "vulnerability": {
        "name": "AIKIDO-2025-10170"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/anyio@3.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/anyio@3.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-63374 affects version 3.7.1.post1+tuxcare of anyio, and is fixed in 3.7.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-63374"
      },
      "action_statement": "Vulnerability CVE-2026-63374 affects version 3.7.1.post1+tuxcare of anyio, and is fixed in 3.7.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/anyio@3.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/anyio@3.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64847 affects version 3.7.1.post1+tuxcare of anyio, and is fixed in 3.7.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-64847"
      },
      "action_statement": "Vulnerability CVE-2026-64847 affects version 3.7.1.post1+tuxcare of anyio, and is fixed in 3.7.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      },
      "action_statement": "Vulnerability CVE-2024-24762 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post1+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      },
      "action_statement": "Vulnerability CVE-2025-54121 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post1+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      },
      "action_statement": "Vulnerability CVE-2026-48710 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      },
      "action_statement": "Vulnerability CVE-2026-48817 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      },
      "action_statement": "Vulnerability CVE-2026-48818 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      },
      "action_statement": "Vulnerability CVE-2026-54282 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      },
      "action_statement": "Vulnerability CVE-2026-54283 affects version 0.27.0.post1+tuxcare of starlette, and is fixed in 0.27.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 is fixed in version 46.0.7.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 46.0.7.post2+tuxcare of cryptography, and is fixed in 46.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 46.0.7.post2+tuxcare of cryptography, and is fixed in 46.0.7.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 46.0.7.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 46.0.7.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.27.0.post7+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post7+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post7+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post7+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post7+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 is fixed in version 0.27.0.post7+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 is fixed in version 0.27.0.post7+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 is fixed in version 0.27.0.post7+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 is fixed in version 0.27.0.post7+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64439 is fixed in version 2.1.2.post3+tuxcare of langgraph-checkpoint.",
      "vulnerability": {
        "name": "CVE-2025-64439"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27794 is fixed in version 2.1.2.post3+tuxcare of langgraph-checkpoint.",
      "vulnerability": {
        "name": "CVE-2026-27794"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48775 is fixed in version 2.1.2.post3+tuxcare of langgraph-checkpoint.",
      "vulnerability": {
        "name": "CVE-2026-48775"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-20916 is fixed in version 9.0.0.post2+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2019-20916"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3572 is fixed in version 9.0.0.post2+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2021-3572"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-5752 is fixed in version 9.0.0.post2+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2023-5752"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-8869 is fixed in version 9.0.0.post2+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2025-8869"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-13346 affects version 9.0.0.post2+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-13346"
      },
      "action_statement": "Vulnerability CVE-2026-13346 affects version 9.0.0.post2+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1703 affects version 9.0.0.post2+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2026-1703"
      },
      "action_statement": "Vulnerability CVE-2026-1703 affects version 9.0.0.post2+tuxcare of pip."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3219 affects version 9.0.0.post2+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-3219"
      },
      "action_statement": "Vulnerability CVE-2026-3219 affects version 9.0.0.post2+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6357 affects version 9.0.0.post2+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6357"
      },
      "action_statement": "Vulnerability CVE-2026-6357 affects version 9.0.0.post2+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8643 is fixed in version 9.0.0.post2+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2026-8643"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-20916 is fixed in version 9.0.post1+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2019-20916"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3572 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-3572"
      },
      "action_statement": "Vulnerability CVE-2021-3572 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-5752 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-5752"
      },
      "action_statement": "Vulnerability CVE-2023-5752 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-8869 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-8869"
      },
      "action_statement": "Vulnerability CVE-2025-8869 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-13346 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-13346"
      },
      "action_statement": "Vulnerability CVE-2026-13346 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1703 affects version 9.0.post1+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2026-1703"
      },
      "action_statement": "Vulnerability CVE-2026-1703 affects version 9.0.post1+tuxcare of pip."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3219 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-3219"
      },
      "action_statement": "Vulnerability CVE-2026-3219 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6357 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6357"
      },
      "action_statement": "Vulnerability CVE-2026-6357 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8643 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8643"
      },
      "action_statement": "Vulnerability CVE-2026-8643 affects version 9.0.post1+tuxcare of pip, and is fixed in 9.0.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.63.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.63.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-32677 is fixed in version 0.63.0.post1+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2021-32677"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.63.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.63.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 affects version 0.63.0.post1+tuxcare of fastapi, and is fixed in 0.63.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      },
      "action_statement": "Vulnerability CVE-2024-24762 affects version 0.63.0.post1+tuxcare of fastapi, and is fixed in 0.63.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.0.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.0.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1135 affects version 20.0.4.post1+tuxcare of gunicorn, and is fixed in 20.0.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1135"
      },
      "action_statement": "Vulnerability CVE-2024-1135 affects version 20.0.4.post1+tuxcare of gunicorn, and is fixed in 20.0.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.0.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.0.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6827 affects version 20.0.4.post1+tuxcare of gunicorn, and is fixed in 20.0.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-6827"
      },
      "action_statement": "Vulnerability CVE-2024-6827 affects version 20.0.4.post1+tuxcare of gunicorn, and is fixed in 20.0.4.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post5+tuxcare of mlflow. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post5+tuxcare of mlflow. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post5+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post5+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post5+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post5+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post5+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post5+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post5+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post5+tuxcare of mlflow. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.22.4.post5+tuxcare of mlflow, and is fixed in 2.22.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.22.4.post5+tuxcare of mlflow, and is fixed in 2.22.4.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post5+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post5+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post5+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post5+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post5+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post5+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@0.12.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@0.12.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-1010083 is fixed in version 0.12.5.post1+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2019-1010083"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/flask@0.12.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@0.12.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30861 affects version 0.12.5.post1+tuxcare of flask, and is fixed in 0.12.5.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-30861"
      },
      "action_statement": "Vulnerability CVE-2023-30861 affects version 0.12.5.post1+tuxcare of flask, and is fixed in 0.12.5.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/flask@0.12.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@0.12.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27205 affects version 0.12.5.post1+tuxcare of flask, and is fixed in 0.12.5.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27205"
      },
      "action_statement": "Vulnerability CVE-2026-27205 affects version 0.12.5.post1+tuxcare of flask, and is fixed in 0.12.5.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-2148 affects version 1.13.1.post1+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-2148"
      },
      "action_statement": "Vulnerability CVE-2025-2148 affects version 1.13.1.post1+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-2149 affects version 1.13.1.post1+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-2149"
      },
      "action_statement": "Vulnerability CVE-2025-2149 affects version 1.13.1.post1+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-2953 affects version 1.13.1.post1+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-2953"
      },
      "action_statement": "Vulnerability CVE-2025-2953 affects version 1.13.1.post1+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-2998 affects version 1.13.1.post1+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-2998"
      },
      "action_statement": "Vulnerability CVE-2025-2998 affects version 1.13.1.post1+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-2999 affects version 1.13.1.post1+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-2999"
      },
      "action_statement": "Vulnerability CVE-2025-2999 affects version 1.13.1.post1+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3000 affects version 1.13.1.post1+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-3000"
      },
      "action_statement": "Vulnerability CVE-2025-3000 affects version 1.13.1.post1+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3001 affects version 1.13.1.post1+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-3001"
      },
      "action_statement": "Vulnerability CVE-2025-3001 affects version 1.13.1.post1+tuxcare of torch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/torch@1.13.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/torch@1.13.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3730 affects version 1.13.1.post1+tuxcare of torch.",
      "vulnerability": {
        "name": "CVE-2025-3730"
      },
      "action_statement": "Vulnerability CVE-2025-3730 affects version 1.13.1.post1+tuxcare of torch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post13+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post13+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post13+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post13+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post13+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post13+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post13+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post13+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post13+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post13+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post13+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post13+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post13+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post13+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post13+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post13+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.5.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post10+tuxcare of mlflow-skinny. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post10+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post10+tuxcare of mlflow-skinny. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post10+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post10+tuxcare of mlflow-skinny."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post10+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post10+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post10+tuxcare of mlflow-skinny."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post10+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post10+tuxcare of mlflow-skinny. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post10+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post10+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm is fixed in version 2.22.4.post10+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-65106 does not affect version 0.3.83.post1+tuxcare of langchain-core. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-65106"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26013 affects version 0.3.83.post1+tuxcare of langchain-core.",
      "vulnerability": {
        "name": "CVE-2026-26013"
      },
      "action_statement": "Vulnerability CVE-2026-26013 affects version 0.3.83.post1+tuxcare of langchain-core."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34070 is fixed in version 0.3.83.post1+tuxcare of langchain-core.",
      "vulnerability": {
        "name": "CVE-2026-34070"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44843 affects version 0.3.83.post1+tuxcare of langchain-core, and is fixed in 0.3.83.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44843"
      },
      "action_statement": "Vulnerability CVE-2026-44843 affects version 0.3.83.post1+tuxcare of langchain-core, and is fixed in 0.3.83.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/paramiko@3.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/paramiko@3.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-48795 is fixed in version 3.0.0.post1+tuxcare of paramiko.",
      "vulnerability": {
        "name": "CVE-2023-48795"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/paramiko@3.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/paramiko@3.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44405 affects version 3.0.0.post1+tuxcare of paramiko, and is fixed in 3.0.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44405"
      },
      "action_statement": "Vulnerability CVE-2026-44405 affects version 3.0.0.post1+tuxcare of paramiko, and is fixed in 3.0.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 affects version 41.0.7.post1+tuxcare of cryptography, and is fixed in 41.0.7.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      },
      "action_statement": "Vulnerability CVE-2024-0727 affects version 41.0.7.post1+tuxcare of cryptography, and is fixed in 41.0.7.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 41.0.7.post1+tuxcare of cryptography, and is fixed in 41.0.7.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 41.0.7.post1+tuxcare of cryptography, and is fixed in 41.0.7.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 41.0.7.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 41.0.7.post1+tuxcare of cryptography."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 41.0.7.post1+tuxcare of cryptography. not_affected \u2014 python-cryptography version 41.0.7.post2+tuxcare is NOT AFFECTED by CVE-2026-69248. The vulnerability exists in the x509 verification module's DNS name constraint matching logic when validating wildcard SANs against intermediate CA constraints. However, the entire x509.verification module (including PolicyBuilder, Store, build_server_verifier, and the Rust cryptography-x509-verification compone...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 python-cryptography version 41.0.7.post2+tuxcare is NOT AFFECTED by CVE-2026-69248. The vulnerability exists in the x509 verification module's DNS name constraint matching logic when validating wildcard SANs against intermediate CA constraints. However, the entire x509.verification module (including PolicyBuilder, Store, build_server_verifier, and the Rust cryptography-x509-verification compone..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 does not affect version 41.0.7.post1+tuxcare of cryptography. not_affected \u2014 Version 41.0.7 is not affected by CVE-2026-69249. The vulnerable x509.verification module with its build_chain_inner function was introduced in cryptography version 42.0.0. Version 41.0.7 predates this feature and has no certificate chain validation API exposed to users. The INPUT type (certificate chains passed to PolicyBuilder.verify()) cannot be received in this version because the entire ve...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "impact_statement": "not_affected \u2014 Version 41.0.7 is not affected by CVE-2026-69249. The vulnerable x509.verification module with its build_chain_inner function was introduced in cryptography version 42.0.0. Version 41.0.7 predates this feature and has no certificate chain validation API exposed to users. The INPUT type (certificate chains passed to PolicyBuilder.verify()) cannot be received in this version because the entire ve..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 41.0.7.post1+tuxcare of cryptography, and is fixed in 41.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 41.0.7.post1+tuxcare of cryptography, and is fixed in 41.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@41.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 41.0.7.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-h4gh-qq45-vh27"
      },
      "action_statement": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 41.0.7.post1+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48379 is fixed in version 11.2.1.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2025-48379"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      },
      "action_statement": "Vulnerability CVE-2026-25990 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 11.2.1.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      },
      "action_statement": "Vulnerability CVE-2026-42309 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 11.2.1.post2+tuxcare of pillow, and is fixed in 11.2.1.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29159 is fixed in version 0.13.6.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2023-29159"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30798 is fixed in version 0.13.6.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2023-30798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.13.6.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.13.6.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.13.6.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:22:44.885595+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.13.6.post5+tuxcare of starlette. starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0)."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 affects version 0.13.6.post5+tuxcare of starlette, and is fixed in 0.13.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      },
      "action_statement": "Vulnerability CVE-2026-48710 affects version 0.13.6.post5+tuxcare of starlette, and is fixed in 0.13.6.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 is fixed in version 0.13.6.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 is fixed in version 0.13.6.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 is fixed in version 0.13.6.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 is fixed in version 0.13.6.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-93gm-qmq6-w238 is fixed in version 0.13.6.post5+tuxcare of starlette.",
      "vulnerability": {
        "name": "GHSA-93gm-qmq6-w238"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.63.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.63.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-32677 is fixed in version 0.63.0.post5+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2021-32677"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.63.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.63.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.63.0.post5+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.104.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.104.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.104.1.post2+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 45.0.7.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 45.0.7.post1+tuxcare of cryptography, and is fixed in 45.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 45.0.7.post1+tuxcare of cryptography, and is fixed in 45.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39892 affects version 45.0.7.post1+tuxcare of cryptography, and is fixed in 45.0.7.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-39892"
      },
      "action_statement": "Vulnerability CVE-2026-39892 affects version 45.0.7.post1+tuxcare of cryptography, and is fixed in 45.0.7.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 affects version 45.0.7.post1+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      },
      "action_statement": "Vulnerability CVE-2026-69247 affects version 45.0.7.post1+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 45.0.7.post1+tuxcare of cryptography, and is fixed in 45.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 45.0.7.post1+tuxcare of cryptography, and is fixed in 45.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 45.0.7.post1+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 45.0.7.post1+tuxcare of cryptography, and is fixed in 45.0.7.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 45.0.7.post1+tuxcare of cryptography. not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/langchain-text-splitters@0.3.11.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langchain-text-splitters@0.3.11.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fv5p-p927-qmxr is fixed in version 0.3.11.post1+tuxcare of langchain-text-splitters.",
      "vulnerability": {
        "name": "GHSA-fv5p-p927-qmxr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@2.2.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@2.2.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27205 is fixed in version 2.2.5.post1+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2026-27205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-0286 is fixed in version 3.4.8.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-0286"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-23931"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-3446 is fixed in version 3.4.8.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-3446"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49083 is fixed in version 3.4.8.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-49083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-50782"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 affects version 3.4.8.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      },
      "action_statement": "Vulnerability CVE-2024-0727 affects version 3.4.8.post5+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12797 is fixed in version 3.4.8.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-12797"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 3.4.8.post5+tuxcare of cryptography, and is fixed in 3.4.8.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 3.4.8.post5+tuxcare of cryptography, and is fixed in 3.4.8.post6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 does not affect version 3.4.8.post5+tuxcare of cryptography. Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "impact_statement": "Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 3.4.8.post5+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 does not affect version 3.4.8.post5+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post5+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons...",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5cpq-8wj7-hf2v does not affect version 3.4.8.post5+tuxcare of cryptography. cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5cpq-8wj7-hf2v"
      },
      "impact_statement": "cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-jm77-qphf-c4w8"
      },
      "action_statement": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post5+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post5+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-v8gr-m533-ghj9"
      },
      "action_statement": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post5+tuxcare of cryptography."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post9+tuxcare of mlflow. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post9+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post9+tuxcare of mlflow. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post9+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post9+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post9+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post9+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post9+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post9+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post9+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post9+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post9+tuxcare of mlflow. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post9+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post9+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm is fixed in version 2.22.4.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2021.10.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2021.10.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23491 affects version 2021.10.8.post3+tuxcare of certifi, and is fixed in 2021.10.8.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-23491"
      },
      "action_statement": "Vulnerability CVE-2022-23491 affects version 2021.10.8.post3+tuxcare of certifi, and is fixed in 2021.10.8.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2021.10.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2021.10.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37920 affects version 2021.10.8.post3+tuxcare of certifi, and is fixed in 2021.10.8.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-37920"
      },
      "action_statement": "Vulnerability CVE-2023-37920 affects version 2021.10.8.post3+tuxcare of certifi, and is fixed in 2021.10.8.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2021.10.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2021.10.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39689 is fixed in version 2021.10.8.post3+tuxcare of certifi.",
      "vulnerability": {
        "name": "CVE-2024-39689"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29159 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2023-29159"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30798 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2023-30798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:22:44.885595+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.13.6.post6+tuxcare of starlette. starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-93gm-qmq6-w238 is fixed in version 0.13.6.post6+tuxcare of starlette.",
      "vulnerability": {
        "name": "GHSA-93gm-qmq6-w238"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-32681 is fixed in version 2.25.1.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2023-32681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-35195 is fixed in version 2.25.1.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2024-35195"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 is fixed in version 2.25.1.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 is fixed in version 2.25.1.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/celery@v5.1.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/celery@v5.1.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-23727 is fixed in version v5.1.2.post1+tuxcare of celery.",
      "vulnerability": {
        "name": "CVE-2021-23727"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2022.12.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2022.12.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37920 is fixed in version 2022.12.7.post3+tuxcare of certifi.",
      "vulnerability": {
        "name": "CVE-2023-37920"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2022.12.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2022.12.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37920 CVE-2024-39689 is fixed in version 2022.12.7.post3+tuxcare of certifi.",
      "vulnerability": {
        "name": "CVE-2023-37920 CVE-2024-39689"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2022.12.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2022.12.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39689 is fixed in version 2022.12.7.post3+tuxcare of certifi.",
      "vulnerability": {
        "name": "CVE-2024-39689"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post3+tuxcare of mlflow. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post3+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post3+tuxcare of mlflow. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post3+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post3+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post3+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post3+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post3+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post3+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post3+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post3+tuxcare of mlflow. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post3+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      },
      "action_statement": "Vulnerability CVE-2026-4137 affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post3+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post3+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48379 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2025-48379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 11.2.1.post5+tuxcare of pillow, and is fixed in 11.2.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 11.2.1.post5+tuxcare of pillow, and is fixed in 11.2.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 11.2.1.post5+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 11.2.1.post5+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 11.2.1.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/uvicorn@0.11.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/uvicorn@0.11.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-7694 is fixed in version 0.11.6.post2+tuxcare of uvicorn.",
      "vulnerability": {
        "name": "CVE-2020-7694"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/uvicorn@0.11.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/uvicorn@0.11.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-7695 is fixed in version 0.11.6.post2+tuxcare of uvicorn.",
      "vulnerability": {
        "name": "CVE-2020-7695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/protobuf@4.24.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/protobuf@4.24.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0994 is fixed in version 4.24.3.post2+tuxcare of protobuf.",
      "vulnerability": {
        "name": "CVE-2026-0994"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29159 is fixed in version 0.13.6.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2023-29159"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30798 is fixed in version 0.13.6.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2023-30798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.13.6.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.13.6.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.13.6.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:22:44.885595+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.13.6.post4+tuxcare of starlette. starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0)."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 affects version 0.13.6.post4+tuxcare of starlette, and is fixed in 0.13.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      },
      "action_statement": "Vulnerability CVE-2026-48710 affects version 0.13.6.post4+tuxcare of starlette, and is fixed in 0.13.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 affects version 0.13.6.post4+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      },
      "action_statement": "Vulnerability CVE-2026-48817 affects version 0.13.6.post4+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 affects version 0.13.6.post4+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      },
      "action_statement": "Vulnerability CVE-2026-48818 affects version 0.13.6.post4+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 affects version 0.13.6.post4+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      },
      "action_statement": "Vulnerability CVE-2026-54282 affects version 0.13.6.post4+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 affects version 0.13.6.post4+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      },
      "action_statement": "Vulnerability CVE-2026-54283 affects version 0.13.6.post4+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-93gm-qmq6-w238 is fixed in version 0.13.6.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "GHSA-93gm-qmq6-w238"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/waitress@2.1.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/waitress@2.1.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49768 is fixed in version 2.1.2.post1+tuxcare of waitress.",
      "vulnerability": {
        "name": "CVE-2024-49768"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/waitress@2.1.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/waitress@2.1.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49769 affects version 2.1.2.post1+tuxcare of waitress, and is fixed in 2.1.2.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-49769"
      },
      "action_statement": "Vulnerability CVE-2024-49769 affects version 2.1.2.post1+tuxcare of waitress, and is fixed in 2.1.2.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/lxml@5.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/lxml@5.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-2309 does not affect version 5.4.0.post1+tuxcare of lxml. already_fixed \u2014 all patch commits already exist in target branch",
      "vulnerability": {
        "name": "CVE-2022-2309"
      },
      "impact_statement": "already_fixed \u2014 all patch commits already exist in target branch"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/lxml@5.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/lxml@5.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41066 is fixed in version 5.4.0.post1+tuxcare of lxml.",
      "vulnerability": {
        "name": "CVE-2026-41066"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 44.0.3.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 is fixed in version 44.0.3.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 is fixed in version 44.0.3.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 is fixed in version 44.0.3.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 44.0.3.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 44.0.3.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33430 is fixed in version 1.16.0.post4+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-33430"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-34141 is fixed in version 1.16.0.post4+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-34141"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.16.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.16.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41495 is fixed in version 1.16.0.post4+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-41495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/statsmodels@0.14.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/statsmodels@0.14.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10275 is fixed in version 0.14.5.post1+tuxcare of statsmodels.",
      "vulnerability": {
        "name": "AIKIDO-2024-10275"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post4+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post4+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-53981"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24486 affects version 0.0.6.post4+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24486"
      },
      "action_statement": "Vulnerability CVE-2026-24486 affects version 0.0.6.post4+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40347 is fixed in version 0.0.6.post4+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-40347"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42561 affects version 0.0.6.post4+tuxcare of python-multipart, and is fixed in 0.0.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42561"
      },
      "action_statement": "Vulnerability CVE-2026-42561 affects version 0.0.6.post4+tuxcare of python-multipart, and is fixed in 0.0.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53537 affects version 0.0.6.post4+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53537"
      },
      "action_statement": "Vulnerability CVE-2026-53537 affects version 0.0.6.post4+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53538 affects version 0.0.6.post4+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53538"
      },
      "action_statement": "Vulnerability CVE-2026-53538 affects version 0.0.6.post4+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53540 is fixed in version 0.0.6.post4+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-53540"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48379 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2025-48379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 11.2.1.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 affects version 0.27.0.post3+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      },
      "action_statement": "Vulnerability CVE-2024-24762 affects version 0.27.0.post3+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post3+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post3+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post3+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post3+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 affects version 0.27.0.post3+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      },
      "action_statement": "Vulnerability CVE-2026-48817 affects version 0.27.0.post3+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 affects version 0.27.0.post3+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      },
      "action_statement": "Vulnerability CVE-2026-48818 affects version 0.27.0.post3+tuxcare of starlette, and is fixed in 0.27.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 affects version 0.27.0.post3+tuxcare of starlette, and is fixed in 0.27.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      },
      "action_statement": "Vulnerability CVE-2026-54282 affects version 0.27.0.post3+tuxcare of starlette, and is fixed in 0.27.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 affects version 0.27.0.post3+tuxcare of starlette, and is fixed in 0.27.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      },
      "action_statement": "Vulnerability CVE-2026-54283 affects version 0.27.0.post3+tuxcare of starlette, and is fixed in 0.27.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48379 is fixed in version 11.2.1.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2025-48379"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      },
      "action_statement": "Vulnerability CVE-2026-25990 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 11.2.1.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 is fixed in version 11.2.1.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      },
      "action_statement": "Vulnerability CVE-2026-42309 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 is fixed in version 11.2.1.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 is fixed in version 11.2.1.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 11.2.1.post3+tuxcare of pillow, and is fixed in 11.2.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 is fixed in version 11.2.1.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.2.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.2.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 11.2.1.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-0286 affects version 3.4.8.post4+tuxcare of cryptography, and is fixed in 3.4.8.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-0286"
      },
      "action_statement": "Vulnerability CVE-2023-0286 affects version 3.4.8.post4+tuxcare of cryptography, and is fixed in 3.4.8.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-23931"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-3446 is fixed in version 3.4.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-3446"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49083 is fixed in version 3.4.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-49083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-50782"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 affects version 3.4.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      },
      "action_statement": "Vulnerability CVE-2024-0727 affects version 3.4.8.post4+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12797 is fixed in version 3.4.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-12797"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 3.4.8.post4+tuxcare of cryptography, and is fixed in 3.4.8.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 3.4.8.post4+tuxcare of cryptography, and is fixed in 3.4.8.post6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 does not affect version 3.4.8.post4+tuxcare of cryptography. Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "impact_statement": "Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 3.4.8.post4+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 does not affect version 3.4.8.post4+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post4+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons...",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5cpq-8wj7-hf2v does not affect version 3.4.8.post4+tuxcare of cryptography. cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5cpq-8wj7-hf2v"
      },
      "impact_statement": "cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-jm77-qphf-c4w8"
      },
      "action_statement": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post4+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-v8gr-m533-ghj9"
      },
      "action_statement": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post4+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.63.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.63.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-32677 is fixed in version 0.63.0.post2+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2021-32677"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.63.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.63.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.63.0.post2+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post6+tuxcare of mlflow. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post6+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post6+tuxcare of mlflow. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post6+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post6+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post6+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post6+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post6+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post6+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post6+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post6+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post6+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post6+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post6+tuxcare of mlflow. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post6+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post6+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post6+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post6+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post6+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post6+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 45.0.7.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 is fixed in version 45.0.7.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39892 is fixed in version 45.0.7.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-39892"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 is fixed in version 45.0.7.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 is fixed in version 45.0.7.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 45.0.7.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@45.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@45.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 45.0.7.post4+tuxcare of cryptography. not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.0.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.0.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1135 is fixed in version 20.0.4.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-1135"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.0.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.0.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6827 is fixed in version 20.0.4.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-6827"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 is fixed in version 2.3.8.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 is fixed in version 2.3.8.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 is fixed in version 2.3.8.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 is fixed in version 2.3.8.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 is fixed in version 2.3.8.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 is fixed in version 2.3.8.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10216 is fixed in version 21.2.0.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "AIKIDO-2024-10216"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1135 is fixed in version 21.2.0.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-1135"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6827 is fixed in version 21.2.0.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-6827"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-7923 is fixed in version 21.2.0.post3+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-7923"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10216 is fixed in version 20.1.0.post2+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "AIKIDO-2024-10216"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10742 affects version 20.1.0.post2+tuxcare of gunicorn, and is fixed in 20.1.0.post3+tuxcare.",
      "vulnerability": {
        "name": "AIKIDO-2026-10742"
      },
      "action_statement": "Vulnerability AIKIDO-2026-10742 affects version 20.1.0.post2+tuxcare of gunicorn, and is fixed in 20.1.0.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1135 is fixed in version 20.1.0.post2+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-1135"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6827 is fixed in version 20.1.0.post2+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-6827"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-7923 is fixed in version 20.1.0.post2+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-7923"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post8+tuxcare of mlflow-skinny. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post8+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post8+tuxcare of mlflow-skinny. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post8+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post8+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post8+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post8+tuxcare of mlflow-skinny."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post8+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post8+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post8+tuxcare of mlflow-skinny."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post8+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post8+tuxcare of mlflow-skinny. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post8+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post8+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 is fixed in version 2.22.4.post8+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post8+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post8+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post3+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post3+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post3+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post3+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post3+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post3+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post3+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post3+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@1.1.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@1.1.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30861 is fixed in version 1.1.2.post2+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2023-30861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@1.1.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@1.1.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27205 is fixed in version 1.1.2.post2+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2026-27205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/statsmodels@0.14.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/statsmodels@0.14.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10275 is fixed in version 0.14.4.post1+tuxcare of statsmodels.",
      "vulnerability": {
        "name": "AIKIDO-2024-10275"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@25.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@25.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27448 is fixed in version 25.3.0.post1+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27448"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@25.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@25.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27459 is fixed in version 25.3.0.post1+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post4+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      },
      "action_statement": "Vulnerability CVE-2023-6940 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post4+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post4+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post4+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      },
      "action_statement": "Vulnerability CVE-2024-1594 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post4+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post4+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      },
      "action_statement": "Vulnerability CVE-2024-37054 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post4+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      },
      "action_statement": "Vulnerability CVE-2024-37058 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post4+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post4+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post4+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      },
      "action_statement": "Vulnerability CVE-2024-4263 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post4+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      },
      "action_statement": "Vulnerability CVE-2025-1474 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post4+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post4+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post4+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post4+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post4+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      },
      "action_statement": "Vulnerability CVE-2026-0596 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post4+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post4+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post4+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post4+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post4+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post4+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post4+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post4+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      },
      "action_statement": "Vulnerability CVE-2026-4137 affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post4+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post4+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.32.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.32.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 is fixed in version 2.32.3.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.32.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.32.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 is fixed in version 2.32.3.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pymongo@3.13.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pymongo@3.13.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-5629 is fixed in version 3.13.0.post1+tuxcare of pymongo.",
      "vulnerability": {
        "name": "CVE-2024-5629"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/celery@4.4.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/celery@4.4.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-23727 is fixed in version 4.4.7.post1+tuxcare of celery.",
      "vulnerability": {
        "name": "CVE-2021-23727"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-21712 is fixed in version 20.3.0.post5+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2022-21712"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-24801 is fixed in version 20.3.0.post5+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2022-24801"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-39348 is fixed in version 20.3.0.post5+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2022-39348"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46137 is fixed in version 20.3.0.post5+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2023-46137"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41671 is fixed in version 20.3.0.post5+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2024-41671"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41810 is fixed in version 20.3.0.post5+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2024-41810"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42304 is fixed in version 20.3.0.post5+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2026-42304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post9+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 affects version 2.9.1.post9+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      },
      "action_statement": "Vulnerability CVE-2023-6940 affects version 2.9.1.post9+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post9+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post9+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post9+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post9+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post9+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 affects version 2.9.1.post9+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      },
      "action_statement": "Vulnerability CVE-2024-37054 affects version 2.9.1.post9+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post9+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post9+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post9+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post9+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post9+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post9+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post9+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post9+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post9+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post9+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post9+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post9+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post9+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post9+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post9+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post9+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post9+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post9+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post9+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm is fixed in version 2.9.1.post9+tuxcare of mlflow.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10318 is fixed in version 2.14.7.post1+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "AIKIDO-2026-10318"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64340 affects version 2.14.7.post1+tuxcare of fastmcp, and is fixed in 2.14.7.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64340"
      },
      "action_statement": "Vulnerability CVE-2025-64340 affects version 2.14.7.post1+tuxcare of fastmcp, and is fixed in 2.14.7.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27124 is fixed in version 2.14.7.post1+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "CVE-2026-27124"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32871 is fixed in version 2.14.7.post1+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "CVE-2026-32871"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@60.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@60.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-40897 affects version 60.0.0.post1+tuxcare of setuptools, and is fixed in 60.0.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-40897"
      },
      "action_statement": "Vulnerability CVE-2022-40897 affects version 60.0.0.post1+tuxcare of setuptools, and is fixed in 60.0.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@60.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@60.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6345 is fixed in version 60.0.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2024-6345"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@60.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@60.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 affects version 60.0.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      },
      "action_statement": "Vulnerability CVE-2025-47273 affects version 60.0.0.post1+tuxcare of setuptools."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@60.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@60.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 affects version 60.0.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      },
      "action_statement": "Vulnerability CVE-2026-59890 affects version 60.0.0.post1+tuxcare of setuptools."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10085 is fixed in version 1.0.1.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10410 is fixed in version 1.0.1.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10410"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23934 is fixed in version 1.0.1.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-23934"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-25577 is fixed in version 1.0.1.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-25577"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46136 is fixed in version 1.0.1.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-46136"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 is fixed in version 1.0.1.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 is fixed in version 1.0.1.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 is fixed in version 1.0.1.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 is fixed in version 1.0.1.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 affects version 1.0.1.post5+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      },
      "action_statement": "Vulnerability CVE-2026-21860 affects version 1.0.1.post5+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 affects version 1.0.1.post5+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      },
      "action_statement": "Vulnerability CVE-2026-27199 affects version 1.0.1.post5+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.32.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.32.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 affects version 2.32.3.post1+tuxcare of requests, and is fixed in 2.32.3.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      },
      "action_statement": "Vulnerability CVE-2024-47081 affects version 2.32.3.post1+tuxcare of requests, and is fixed in 2.32.3.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.32.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.32.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 affects version 2.32.3.post1+tuxcare of requests, and is fixed in 2.32.3.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      },
      "action_statement": "Vulnerability CVE-2026-25645 affects version 2.32.3.post1+tuxcare of requests, and is fixed in 2.32.3.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post6+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post6+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-53981"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24486 affects version 0.0.6.post6+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24486"
      },
      "action_statement": "Vulnerability CVE-2026-24486 affects version 0.0.6.post6+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40347 is fixed in version 0.0.6.post6+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-40347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42561 is fixed in version 0.0.6.post6+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-42561"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53537 is fixed in version 0.0.6.post6+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-53537"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53538 is fixed in version 0.0.6.post6+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-53538"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53540 is fixed in version 0.0.6.post6+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-53540"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jaraco-context@5.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jaraco-context@5.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-23949 is fixed in version 5.3.0.post1+tuxcare of jaraco-context.",
      "vulnerability": {
        "name": "CVE-2026-23949"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 43.0.1.post2+tuxcare of cryptography, and is fixed in 43.0.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 43.0.1.post2+tuxcare of cryptography, and is fixed in 43.0.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 43.0.1.post2+tuxcare of cryptography, and is fixed in 43.0.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 43.0.1.post2+tuxcare of cryptography, and is fixed in 43.0.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 43.0.1.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 43.0.1.post2+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 43.0.1.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.1.post2+tuxcare of cryptography, and is fixed in 43.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.1.post2+tuxcare of cryptography, and is fixed in 43.0.1.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post5+tuxcare of mlflow-skinny. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post5+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post5+tuxcare of mlflow-skinny. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post5+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post5+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post5+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post5+tuxcare of mlflow-skinny."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post5+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post5+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post5+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post5+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post5+tuxcare of mlflow-skinny."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post5+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post5+tuxcare of mlflow-skinny. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post5+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.22.4.post5+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.22.4.post5+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post5+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post5+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post5+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post5+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post5+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post5+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pydantic@v1.10.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pydantic@v1.10.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3772 is fixed in version v1.10.5.post1+tuxcare of pydantic.",
      "vulnerability": {
        "name": "CVE-2024-3772"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.31.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.31.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-35195 is fixed in version 2.31.0.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2024-35195"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.31.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.31.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 is fixed in version 2.31.0.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.31.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.31.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 is fixed in version 2.31.0.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pdfkit@0.6.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pdfkit@0.6.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25765 affects version 0.6.1.post1+tuxcare of pdfkit.",
      "vulnerability": {
        "name": "CVE-2022-25765"
      },
      "action_statement": "Vulnerability CVE-2022-25765 affects version 0.6.1.post1+tuxcare of pdfkit."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pdfkit@0.6.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pdfkit@0.6.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26240 is fixed in version 0.6.1.post1+tuxcare of pdfkit.",
      "vulnerability": {
        "name": "CVE-2025-26240"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-0286 affects version 3.4.8.post1+tuxcare of cryptography, and is fixed in 3.4.8.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-0286"
      },
      "action_statement": "Vulnerability CVE-2023-0286 affects version 3.4.8.post1+tuxcare of cryptography, and is fixed in 3.4.8.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-23931"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-3446 affects version 3.4.8.post1+tuxcare of cryptography, and is fixed in 3.4.8.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-3446"
      },
      "action_statement": "Vulnerability CVE-2023-3446 affects version 3.4.8.post1+tuxcare of cryptography, and is fixed in 3.4.8.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49083 affects version 3.4.8.post1+tuxcare of cryptography, and is fixed in 3.4.8.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49083"
      },
      "action_statement": "Vulnerability CVE-2023-49083 affects version 3.4.8.post1+tuxcare of cryptography, and is fixed in 3.4.8.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-50782"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 affects version 3.4.8.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      },
      "action_statement": "Vulnerability CVE-2024-0727 affects version 3.4.8.post1+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12797 affects version 3.4.8.post1+tuxcare of cryptography, and is fixed in 3.4.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-12797"
      },
      "action_statement": "Vulnerability CVE-2024-12797 affects version 3.4.8.post1+tuxcare of cryptography, and is fixed in 3.4.8.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 3.4.8.post1+tuxcare of cryptography, and is fixed in 3.4.8.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 3.4.8.post1+tuxcare of cryptography, and is fixed in 3.4.8.post6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 does not affect version 3.4.8.post1+tuxcare of cryptography. Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "impact_statement": "Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 3.4.8.post1+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 does not affect version 3.4.8.post1+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post1+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons...",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5cpq-8wj7-hf2v does not affect version 3.4.8.post1+tuxcare of cryptography. cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5cpq-8wj7-hf2v"
      },
      "impact_statement": "cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-jm77-qphf-c4w8"
      },
      "action_statement": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post1+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-v8gr-m533-ghj9"
      },
      "action_statement": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post1+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@2.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@2.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30861 is fixed in version 2.2.1.post2+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2023-30861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@2.2.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@2.2.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27205 is fixed in version 2.2.1.post2+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2026-27205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10085 is fixed in version 1.0.1.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10410 is fixed in version 1.0.1.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10410"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23934 is fixed in version 1.0.1.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-23934"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-25577 is fixed in version 1.0.1.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-25577"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46136 affects version 1.0.1.post3+tuxcare of werkzeug, and is fixed in 1.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46136"
      },
      "action_statement": "Vulnerability CVE-2023-46136 affects version 1.0.1.post3+tuxcare of werkzeug, and is fixed in 1.0.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 is fixed in version 1.0.1.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 is fixed in version 1.0.1.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 is fixed in version 1.0.1.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 affects version 1.0.1.post3+tuxcare of werkzeug, and is fixed in 1.0.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      },
      "action_statement": "Vulnerability CVE-2025-66221 affects version 1.0.1.post3+tuxcare of werkzeug, and is fixed in 1.0.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 affects version 1.0.1.post3+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      },
      "action_statement": "Vulnerability CVE-2026-21860 affects version 1.0.1.post3+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 affects version 1.0.1.post3+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      },
      "action_statement": "Vulnerability CVE-2026-27199 affects version 1.0.1.post3+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/waitress@2.1.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/waitress@2.1.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49768 is fixed in version 2.1.2.post2+tuxcare of waitress.",
      "vulnerability": {
        "name": "CVE-2024-49768"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/waitress@2.1.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/waitress@2.1.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49769 is fixed in version 2.1.2.post2+tuxcare of waitress.",
      "vulnerability": {
        "name": "CVE-2024-49769"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post3+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post3+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-53981"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24486 affects version 0.0.6.post3+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24486"
      },
      "action_statement": "Vulnerability CVE-2026-24486 affects version 0.0.6.post3+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40347 is fixed in version 0.0.6.post3+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-40347"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42561 affects version 0.0.6.post3+tuxcare of python-multipart, and is fixed in 0.0.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42561"
      },
      "action_statement": "Vulnerability CVE-2026-42561 affects version 0.0.6.post3+tuxcare of python-multipart, and is fixed in 0.0.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53537 affects version 0.0.6.post3+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53537"
      },
      "action_statement": "Vulnerability CVE-2026-53537 affects version 0.0.6.post3+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53538 affects version 0.0.6.post3+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53538"
      },
      "action_statement": "Vulnerability CVE-2026-53538 affects version 0.0.6.post3+tuxcare of python-multipart, and is fixed in 0.0.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53540 affects version 0.0.6.post3+tuxcare of python-multipart, and is fixed in 0.0.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53540"
      },
      "action_statement": "Vulnerability CVE-2026-53540 affects version 0.0.6.post3+tuxcare of python-multipart, and is fixed in 0.0.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 affects version 0.27.0.post4+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      },
      "action_statement": "Vulnerability CVE-2024-24762 affects version 0.27.0.post4+tuxcare of starlette, and is fixed in 0.27.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post4+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 is fixed in version 0.27.0.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 is fixed in version 0.27.0.post4+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 affects version 0.27.0.post4+tuxcare of starlette, and is fixed in 0.27.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      },
      "action_statement": "Vulnerability CVE-2026-54282 affects version 0.27.0.post4+tuxcare of starlette, and is fixed in 0.27.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 affects version 0.27.0.post4+tuxcare of starlette, and is fixed in 0.27.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      },
      "action_statement": "Vulnerability CVE-2026-54283 affects version 0.27.0.post4+tuxcare of starlette, and is fixed in 0.27.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2022.12.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2022.12.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37920 affects version 2022.12.7.post1+tuxcare of certifi, and is fixed in 2022.12.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-37920"
      },
      "action_statement": "Vulnerability CVE-2023-37920 affects version 2022.12.7.post1+tuxcare of certifi, and is fixed in 2022.12.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2022.12.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2022.12.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37920 CVE-2024-39689 affects version 2022.12.7.post1+tuxcare of certifi, and is fixed in 2022.12.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-37920 CVE-2024-39689"
      },
      "action_statement": "Vulnerability CVE-2023-37920 CVE-2024-39689 affects version 2022.12.7.post1+tuxcare of certifi, and is fixed in 2022.12.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2022.12.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2022.12.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39689 affects version 2022.12.7.post1+tuxcare of certifi, and is fixed in 2022.12.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39689"
      },
      "action_statement": "Vulnerability CVE-2024-39689 affects version 2022.12.7.post1+tuxcare of certifi, and is fixed in 2022.12.7.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@1.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@1.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30861 is fixed in version 1.1.4.post1+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2023-30861"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/flask@1.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@1.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27205 affects version 1.1.4.post1+tuxcare of flask, and is fixed in 1.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27205"
      },
      "action_statement": "Vulnerability CVE-2026-27205 affects version 1.1.4.post1+tuxcare of flask, and is fixed in 1.1.4.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/google-cloud-storage@2.19.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/google-cloud-storage@2.19.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10425 is fixed in version 2.19.0.post2+tuxcare of google-cloud-storage.",
      "vulnerability": {
        "name": "AIKIDO-2026-10425"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@3.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22195 is fixed in version 3.0.3.post1+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-22195"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@3.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34064 affects version 3.0.3.post1+tuxcare of jinja2, and is fixed in 3.0.3.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-34064"
      },
      "action_statement": "Vulnerability CVE-2024-34064 affects version 3.0.3.post1+tuxcare of jinja2, and is fixed in 3.0.3.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@3.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56201 is fixed in version 3.0.3.post1+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-56201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@3.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56326 is fixed in version 3.0.3.post1+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-56326"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@3.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27516 affects version 3.0.3.post1+tuxcare of jinja2, and is fixed in 3.0.3.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27516"
      },
      "action_statement": "Vulnerability CVE-2025-27516 affects version 3.0.3.post1+tuxcare of jinja2, and is fixed in 3.0.3.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post2+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      },
      "action_statement": "Vulnerability CVE-2023-6940 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post2+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      },
      "action_statement": "Vulnerability CVE-2024-1483 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post2+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post2+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      },
      "action_statement": "Vulnerability CVE-2024-1594 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post2+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post2+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      },
      "action_statement": "Vulnerability CVE-2024-37053 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      },
      "action_statement": "Vulnerability CVE-2024-37054 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      },
      "action_statement": "Vulnerability CVE-2024-37055 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post2+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      },
      "action_statement": "Vulnerability CVE-2024-37058 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post2+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post2+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post2+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      },
      "action_statement": "Vulnerability CVE-2024-4263 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      },
      "action_statement": "Vulnerability CVE-2024-6838 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      },
      "action_statement": "Vulnerability CVE-2024-8859 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post2+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      },
      "action_statement": "Vulnerability CVE-2025-11200 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      },
      "action_statement": "Vulnerability CVE-2025-11201 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      },
      "action_statement": "Vulnerability CVE-2025-1474 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post2+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post2+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post2+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post2+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post2+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      },
      "action_statement": "Vulnerability CVE-2026-0596 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post2+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post2+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post2+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post2+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post2+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post2+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post2+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post2+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post2+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      },
      "action_statement": "Vulnerability CVE-2026-4137 affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post2+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post2+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29159 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-29159"
      },
      "action_statement": "Vulnerability CVE-2023-29159 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30798 is fixed in version 0.13.6.post3+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2023-30798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      },
      "action_statement": "Vulnerability CVE-2024-24762 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      },
      "action_statement": "Vulnerability CVE-2024-47874 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.13.6.post3+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:22:44.885595+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.13.6.post3+tuxcare of starlette. starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0)."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      },
      "action_statement": "Vulnerability CVE-2026-48710 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      },
      "action_statement": "Vulnerability CVE-2026-48817 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      },
      "action_statement": "Vulnerability CVE-2026-48818 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      },
      "action_statement": "Vulnerability CVE-2026-54282 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      },
      "action_statement": "Vulnerability CVE-2026-54283 affects version 0.13.6.post3+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-93gm-qmq6-w238 is fixed in version 0.13.6.post3+tuxcare of starlette.",
      "vulnerability": {
        "name": "GHSA-93gm-qmq6-w238"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/uvicorn@0.11.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/uvicorn@0.11.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-7694 is fixed in version 0.11.6.post1+tuxcare of uvicorn.",
      "vulnerability": {
        "name": "CVE-2020-7694"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/uvicorn@0.11.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/uvicorn@0.11.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-7695 is fixed in version 0.11.6.post1+tuxcare of uvicorn.",
      "vulnerability": {
        "name": "CVE-2020-7695"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post9+tuxcare of mlflow-skinny. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post9+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post9+tuxcare of mlflow-skinny. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post9+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post9+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post9+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post9+tuxcare of mlflow-skinny."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post9+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post9+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post9+tuxcare of mlflow-skinny."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post9+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post9+tuxcare of mlflow-skinny. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post9+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post9+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm is fixed in version 2.22.4.post9+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pytest@8.4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pytest@8.4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-71176 is fixed in version 8.4.2.post1+tuxcare of pytest.",
      "vulnerability": {
        "name": "CVE-2025-71176"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/idna@3.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/idna@3.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3651 is fixed in version 3.6.post2+tuxcare of idna.",
      "vulnerability": {
        "name": "CVE-2024-3651"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/idna@3.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/idna@3.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45409 is fixed in version 3.6.post2+tuxcare of idna.",
      "vulnerability": {
        "name": "CVE-2026-45409"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post16+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post16+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post16+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post16+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post16+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post16+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post16+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post16+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post16+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post16+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post16+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post16+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post16+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post16+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.5.post16+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-32681 is fixed in version 2.30.0.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2023-32681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-35195 is fixed in version 2.30.0.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2024-35195"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 is fixed in version 2.30.0.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.30.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.30.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 is fixed in version 2.30.0.post3+tuxcare of requests.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@65.5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@65.5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6345 is fixed in version 65.5.1.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2024-6345"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@65.5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@65.5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 affects version 65.5.1.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      },
      "action_statement": "Vulnerability CVE-2025-47273 affects version 65.5.1.post1+tuxcare of setuptools."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@65.5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@65.5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 affects version 65.5.1.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      },
      "action_statement": "Vulnerability CVE-2026-59890 affects version 65.5.1.post1+tuxcare of setuptools."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6839 is fixed in version 5.0.1.post1+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6839"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6844 is fixed in version 5.0.1.post1+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6844"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6866 is fixed in version 5.0.1.post1+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6866"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/paramiko@2.12.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/paramiko@2.12.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-48795 is fixed in version 2.12.0.post1+tuxcare of paramiko.",
      "vulnerability": {
        "name": "CVE-2023-48795"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/paramiko@2.12.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/paramiko@2.12.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44405 is fixed in version 2.12.0.post1+tuxcare of paramiko.",
      "vulnerability": {
        "name": "CVE-2026-44405"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 affects version 46.0.7.post1+tuxcare of cryptography, and is fixed in 46.0.7.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      },
      "action_statement": "Vulnerability CVE-2026-69247 affects version 46.0.7.post1+tuxcare of cryptography, and is fixed in 46.0.7.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 46.0.7.post1+tuxcare of cryptography, and is fixed in 46.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 46.0.7.post1+tuxcare of cryptography, and is fixed in 46.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 46.0.7.post1+tuxcare of cryptography, and is fixed in 46.0.7.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 46.0.7.post1+tuxcare of cryptography, and is fixed in 46.0.7.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@46.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@46.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 46.0.7.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10086 is fixed in version 2.11.3.post1+tuxcare of jinja2.",
      "vulnerability": {
        "name": "AIKIDO-2024-10086"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10560 is fixed in version 2.11.3.post1+tuxcare of jinja2.",
      "vulnerability": {
        "name": "AIKIDO-2024-10560"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22195 is fixed in version 2.11.3.post1+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-22195"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34064 is fixed in version 2.11.3.post1+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-34064"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56201 affects version 2.11.3.post1+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-56201"
      },
      "action_statement": "Vulnerability CVE-2024-56201 affects version 2.11.3.post1+tuxcare of jinja2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56326 affects version 2.11.3.post1+tuxcare of jinja2, and is fixed in 2.11.3.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56326"
      },
      "action_statement": "Vulnerability CVE-2024-56326 affects version 2.11.3.post1+tuxcare of jinja2, and is fixed in 2.11.3.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27516 affects version 2.11.3.post1+tuxcare of jinja2, and is fixed in 2.11.3.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27516"
      },
      "action_statement": "Vulnerability CVE-2025-27516 affects version 2.11.3.post1+tuxcare of jinja2, and is fixed in 2.11.3.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/certifi@2023.7.22.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/certifi@2023.7.22.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39689 affects version 2023.7.22.post1+tuxcare of certifi, and is fixed in 2023.7.22.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39689"
      },
      "action_statement": "Vulnerability CVE-2024-39689 affects version 2023.7.22.post1+tuxcare of certifi, and is fixed in 2023.7.22.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10085 is fixed in version 2.2.3.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10410 is fixed in version 2.2.3.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10410"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46136 is fixed in version 2.2.3.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-46136"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 is fixed in version 2.2.3.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 is fixed in version 2.2.3.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 is fixed in version 2.2.3.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 affects version 2.2.3.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      },
      "action_statement": "Vulnerability CVE-2025-66221 affects version 2.2.3.post5+tuxcare of werkzeug."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 is fixed in version 2.2.3.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 is fixed in version 2.2.3.post5+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/protobuf@3.17.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/protobuf@3.17.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-4565 affects version 3.17.0.post1+tuxcare of protobuf.",
      "vulnerability": {
        "name": "CVE-2025-4565"
      },
      "action_statement": "Vulnerability CVE-2025-4565 affects version 3.17.0.post1+tuxcare of protobuf."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/protobuf@3.17.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/protobuf@3.17.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0994 does not affect version 3.17.0.post1+tuxcare of protobuf. protobuf 3.17.0 has no recursion-depth limit to bypass. CVE-2026-0994 is a bypass of json_format's max_recursion_depth: _ConvertAnyMessage dispatched well-known types through methodcaller, skipping ConvertMessage and therefore the depth counter. On 3.17.0 there is no counter and no limit - the strings recursion_depth and max_recursion_depth do not occur anywhere in python/google/protobuf/json_format.py, ConvertMessage is declared (self, value, message) with no path argument, and the entry points expose no such parameter (3.17.0: ParseDict(js_dict, message, ignore_unknown_fields=False, descriptor_pool=None); 4.24.3: the same plus max_recursion_depth=100). Upstream's regression tests for this CVE call ParseDict(..., max_recursion_depth=5) and would raise TypeError here rather than exercise the fix. The guarded feature was introduced by a later upstream change, so the code this CVE concerns is not present. Stated separately so it is not lost: having no limit at all leaves 3.17.0 exposed to the unbounded-recursion issue that the limit was introduced to fix - a different vulnerability, not covered by this assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0994"
      },
      "impact_statement": "protobuf 3.17.0 has no recursion-depth limit to bypass. CVE-2026-0994 is a bypass of json_format's max_recursion_depth: _ConvertAnyMessage dispatched well-known types through methodcaller, skipping ConvertMessage and therefore the depth counter. On 3.17.0 there is no counter and no limit - the strings recursion_depth and max_recursion_depth do not occur anywhere in python/google/protobuf/json_format.py, ConvertMessage is declared (self, value, message) with no path argument, and the entry points expose no such parameter (3.17.0: ParseDict(js_dict, message, ignore_unknown_fields=False, descriptor_pool=None); 4.24.3: the same plus max_recursion_depth=100). Upstream's regression tests for this CVE call ParseDict(..., max_recursion_depth=5) and would raise TypeError here rather than exercise the fix. The guarded feature was introduced by a later upstream change, so the code this CVE concerns is not present. Stated separately so it is not lost: having no limit at all leaves 3.17.0 exposed to the unbounded-recursion issue that the limit was introduced to fix - a different vulnerability, not covered by this assessment."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29159 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-29159"
      },
      "action_statement": "Vulnerability CVE-2023-29159 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30798 is fixed in version 0.13.6.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2023-30798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      },
      "action_statement": "Vulnerability CVE-2024-24762 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      },
      "action_statement": "Vulnerability CVE-2024-47874 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.13.6.post2+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:22:44.885595+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.13.6.post2+tuxcare of starlette. starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "starlette 0.13.6 is not vulnerable to CVE-2025-62727: the quadratic Range-header parsing/merging in FileResponse was introduced in 0.39.0; responses.py on tuxcare-current/0.13.6 contains no Range handling at all (verified 2026-09-25, esultanaliev). Same conclusion as the leader VPV 81209 (0.27.0)."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      },
      "action_statement": "Vulnerability CVE-2026-48710 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      },
      "action_statement": "Vulnerability CVE-2026-48817 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      },
      "action_statement": "Vulnerability CVE-2026-48818 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      },
      "action_statement": "Vulnerability CVE-2026-54282 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      },
      "action_statement": "Vulnerability CVE-2026-54283 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-93gm-qmq6-w238 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-93gm-qmq6-w238"
      },
      "action_statement": "Vulnerability GHSA-93gm-qmq6-w238 affects version 0.13.6.post2+tuxcare of starlette, and is fixed in 0.13.6.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/scikit-learn@1.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/scikit-learn@1.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-5206 is fixed in version 1.0.2.post2+tuxcare of scikit-learn.",
      "vulnerability": {
        "name": "CVE-2024-5206"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10318 is fixed in version 2.14.7.post2+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "AIKIDO-2026-10318"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64340 is fixed in version 2.14.7.post2+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "CVE-2025-64340"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27124 is fixed in version 2.14.7.post2+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "CVE-2026-27124"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32871 is fixed in version 2.14.7.post2+tuxcare of fastmcp.",
      "vulnerability": {
        "name": "CVE-2026-32871"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post4+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post4+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post4+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post4+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post4+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post4+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post4+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post4+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/idna@2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/idna@2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3651 is fixed in version 2.1.post1+tuxcare of idna.",
      "vulnerability": {
        "name": "CVE-2024-3651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/idna@2.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/idna@2.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45409 affects version 2.1.post1+tuxcare of idna.",
      "vulnerability": {
        "name": "CVE-2026-45409"
      },
      "action_statement": "Vulnerability CVE-2026-45409 affects version 2.1.post1+tuxcare of idna."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@3.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@3.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22195 is fixed in version 3.0.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-22195"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@3.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@3.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34064 is fixed in version 3.0.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-34064"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@3.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@3.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56201 is fixed in version 3.0.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-56201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@3.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@3.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56326 is fixed in version 3.0.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-56326"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@3.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@3.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27516 is fixed in version 3.0.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2025-27516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@0.12.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@0.12.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-1010083 is fixed in version 0.12.5.post2+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2019-1010083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@0.12.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@0.12.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30861 is fixed in version 0.12.5.post2+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2023-30861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@0.12.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@0.12.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27205 is fixed in version 0.12.5.post2+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2026-27205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10085 is fixed in version 2.2.3.post1+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10410 is fixed in version 2.2.3.post1+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10410"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46136 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46136"
      },
      "action_statement": "Vulnerability CVE-2023-46136 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      },
      "action_statement": "Vulnerability CVE-2024-34069 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      },
      "action_statement": "Vulnerability CVE-2024-49766 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      },
      "action_statement": "Vulnerability CVE-2024-49767 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 affects version 2.2.3.post1+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      },
      "action_statement": "Vulnerability CVE-2025-66221 affects version 2.2.3.post1+tuxcare of werkzeug."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      },
      "action_statement": "Vulnerability CVE-2026-21860 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      },
      "action_statement": "Vulnerability CVE-2026-27199 affects version 2.2.3.post1+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@1.1.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@1.1.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30861 is fixed in version 1.1.2.post1+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2023-30861"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/flask@1.1.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@1.1.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27205 affects version 1.1.2.post1+tuxcare of flask, and is fixed in 1.1.2.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27205"
      },
      "action_statement": "Vulnerability CVE-2026-27205 affects version 1.1.2.post1+tuxcare of flask, and is fixed in 1.1.2.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-0286 affects version 3.4.8.post2+tuxcare of cryptography, and is fixed in 3.4.8.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-0286"
      },
      "action_statement": "Vulnerability CVE-2023-0286 affects version 3.4.8.post2+tuxcare of cryptography, and is fixed in 3.4.8.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-23931"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-3446 is fixed in version 3.4.8.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-3446"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49083 affects version 3.4.8.post2+tuxcare of cryptography, and is fixed in 3.4.8.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49083"
      },
      "action_statement": "Vulnerability CVE-2023-49083 affects version 3.4.8.post2+tuxcare of cryptography, and is fixed in 3.4.8.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2023-50782"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 affects version 3.4.8.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      },
      "action_statement": "Vulnerability CVE-2024-0727 affects version 3.4.8.post2+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12797 affects version 3.4.8.post2+tuxcare of cryptography, and is fixed in 3.4.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-12797"
      },
      "action_statement": "Vulnerability CVE-2024-12797 affects version 3.4.8.post2+tuxcare of cryptography, and is fixed in 3.4.8.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 3.4.8.post2+tuxcare of cryptography, and is fixed in 3.4.8.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 3.4.8.post2+tuxcare of cryptography, and is fixed in 3.4.8.post6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 does not affect version 3.4.8.post2+tuxcare of cryptography. Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "impact_statement": "Not affected. CVE-2026-34073 (GHSA-m959-cc7f-wv43) is a defect in cryptography's own X.509 path validator: DNS name constraints were validated only against SANs in child certificates and not against the peer name presented at validation time. The upstream fix (pyca/cryptography 91d728897bdad30cd5c79a2b23e207f1f050d587, cherry-pick of #14542) changes production code only in src/rust/cryptography-x509-verification/{lib.rs,types.rs}, plus tests/x509/verification/test_limbo.py. That crate -- and its predecessor name cryptography-x509-validation -- first ships in tag 42.0.0. cryptography 3.4.8 does not contain it: src/rust holds only an empty _rust pymodule stub, there is no cryptography.x509.verification module, and no PolicyBuilder/Store/ClientVerifier/ServerVerifier/VerificationError. Verified empirically on the installed package -- 3.4.8 and 41.0.7: import of cryptography.x509.verification raises ModuleNotFoundError and none of the verifier symbols exist; 42.0.8: the module is present -- and on our shipped tree at tag tuxcare-release/3.4.8/3.4.8.post5+tuxcare, which likewise has no verification crate. NameConstraints in 3.4.8 is ASN.1 parse/encode of the extension only (x509/extensions.py, _decode/_encode_name_constraints); there is no chain building and no peer-name matching, so the vulnerable code path does not exist. 3.4.8 is flagged only because OSV declares the affected range as introduced:0 / fixed:46.0.6, which lists all 151 versions from 0.1 onwards rather than scoping it to 42.0.0+. Assessed and closed Won't Fix in PYELSCVE-644 on 2026-04-08. This VPV had been parked in patch_application_parent_pending behind leader VPV 46321 (cryptography 45.0.7), which has since released as 45.0.7.post3+tuxcare, so the follower never unblocked."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 3.4.8.post2+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 is not affected by CVE-2026-69248. The vulnerability exists in python-cryptography's x509.verification module, which was introduced in version 42.0.0 (September 2023). Version 3.4.8, released in August 2021, predates this module by over two years and contains no certificate chain verification functionality. The CVE describes a bug in DNS wildcard name constraint matching within th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 does not affect version 3.4.8.post2+tuxcare of cryptography. not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "impact_statement": "not_affected \u2014 Version 3.4.8 does not contain the cryptography.x509.verification module or the cryptography-x509-verification Rust crate where the vulnerable build_chain_inner function resides. Certificate chain validation functionality was introduced 11 major versions later in version 42.0.0 (released 2024). Version 3.4.8 provides certificate parsing and building capabilities only, not chain validation. The ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post2+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons...",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5cpq-8wj7-hf2v does not affect version 3.4.8.post2+tuxcare of cryptography. cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5cpq-8wj7-hf2v"
      },
      "impact_statement": "cryptography 3.4.8 has no Rust x509 stack (src/rust/src/lib.rs is an empty pymodule stub); certificate and OCSP parsing go through OpenSSL via CFFI. The upstream fix 93c96b777 changes cryptography-x509/src/common.rs, x509/ocsp.rs and x509/sign.rs, none of which exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-jm77-qphf-c4w8"
      },
      "action_statement": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post2+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-v8gr-m533-ghj9"
      },
      "action_statement": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post2+tuxcare of cryptography."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post4+tuxcare of mlflow. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post4+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post4+tuxcare of mlflow. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post4+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post4+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post4+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post4+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post4+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post4+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post4+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post4+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post4+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post4+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post4+tuxcare of mlflow. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post4+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.22.4.post4+tuxcare of mlflow, and is fixed in 2.22.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.22.4.post4+tuxcare of mlflow, and is fixed in 2.22.4.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post4+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post4+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post4+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post4+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post4+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post4+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10085 is fixed in version 1.0.1.post2+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10085"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10410 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post3+tuxcare.",
      "vulnerability": {
        "name": "AIKIDO-2024-10410"
      },
      "action_statement": "Vulnerability AIKIDO-2024-10410 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23934 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-23934"
      },
      "action_statement": "Vulnerability CVE-2023-23934 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-25577 is fixed in version 1.0.1.post2+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-25577"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46136 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46136"
      },
      "action_statement": "Vulnerability CVE-2023-46136 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 is fixed in version 1.0.1.post2+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 is fixed in version 1.0.1.post2+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 is fixed in version 1.0.1.post2+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      },
      "action_statement": "Vulnerability CVE-2025-66221 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      },
      "action_statement": "Vulnerability CVE-2026-21860 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      },
      "action_statement": "Vulnerability CVE-2026-27199 affects version 1.0.1.post2+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post11+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post11+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post11+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post11+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post11+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post11+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post11+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post11+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post11+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post11+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post11+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post11+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post11+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post11+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post11+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post11+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post11+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post11+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post11+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post11+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post11+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post11+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post11+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post11+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post11+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm is fixed in version 2.9.1.post11+tuxcare of mlflow.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/lxml@4.9.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/lxml@4.9.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-2309 affects version 4.9.4.post1+tuxcare of lxml.",
      "vulnerability": {
        "name": "CVE-2022-2309"
      },
      "action_statement": "Vulnerability CVE-2022-2309 affects version 4.9.4.post1+tuxcare of lxml."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/lxml@4.9.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/lxml@4.9.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41066 is fixed in version 4.9.4.post1+tuxcare of lxml.",
      "vulnerability": {
        "name": "CVE-2026-41066"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post6+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post6+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post6+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post6+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post6+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post6+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post6+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post6+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6753"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6831 does not affect version 2.9.1.post6+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2023-6831"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6909"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6940 affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-6940"
      },
      "action_statement": "Vulnerability CVE-2023-6940 affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6974"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2023-6975"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-6976 does not affect version 2.9.1.post6+tuxcare of mlflow. already_fixed \u2014 patches already applied in target branch",
      "vulnerability": {
        "name": "CVE-2023-6976"
      },
      "impact_statement": "already_fixed \u2014 patches already applied in target branch"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1483 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1483"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1558 does not affect version 2.9.1.post6+tuxcare of mlflow. Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')",
      "vulnerability": {
        "name": "CVE-2024-1558"
      },
      "impact_statement": "Patches already applied: 7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654 (already in target via c8405983e7 'Backport CVE-2024-8859 to 2.9.1')"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1560 does not affect version 2.9.1.post6+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2024-1560"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-1593"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1594 affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-1594"
      },
      "action_statement": "Vulnerability CVE-2024-1594 affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27132"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-27134"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-2928"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3099 affects version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3099"
      },
      "action_statement": "Vulnerability CVE-2024-3099 affects version 2.9.1.post6+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-3573"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post6+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37052"
      },
      "impact_statement": "already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37053 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37053"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-37054 affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37054"
      },
      "action_statement": "Vulnerability CVE-2024-37054 affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37055 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37055"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37056"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37057 does not affect version 2.9.1.post6+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37057"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37057 (TensorFlow custom_objects cloudpickle): upstream has no 'fixed' version; its remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#21404, commit dd73d16). tuxcare-current/2.9.1 carries it: cf8bc9c262 (MR !36) = upstream dd73d16, mlflow/tensorflow/__init__.py:537-546 raises when the flag is false; shipped in 2.9.1.post9+tuxcare and later. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37058 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-37058"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.9.1.post6+tuxcare of mlflow. already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-37059 (PyTorch torch.load pickle): upstream remediation is the MLFLOW_ALLOW_PICKLE_DESERIALIZATION control (mlflow#20267 + #21404). tuxcare-current/2.9.1 carries it: 98a32847aa (= upstream #20267) and cf8bc9c262 (= dd73d16); mlflow/pytorch/__init__.py:598-615 `_load_by_pickle_check` runs before every torch.load. Shipped in 2.9.1.post10+tuxcare and earlier. Same conclusion as 2.22.4 VPV 18605 (not_affected, already_fixed). Was parked behind leader 18605. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37060 does not affect version 2.9.1.post6+tuxcare of mlflow. CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37060"
      },
      "impact_statement": "CVE-2024-37060 (Recipes): no upstream fix exists (GHSA-cv6c-7963-wxcg, no patched version). MLflow Recipes executes user-supplied code referenced from recipe.yaml and unpickles its own step outputs (mlflow/recipes/steps/train.py:380, mlflow/recipes/cards/__init__.py:227); running an untrusted recipe is by design equivalent to running untrusted code. Upstream never hardened this path and removed the Recipes feature entirely in MLflow 3.0 (commit 5f3334fa4f, 2025-04-29). Same decision as mlflow 2.22.4 (PYELSCVE-435 Won't Fix, Aikido informed 2025-12-18). Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37061 does not affect version 2.9.1.post6+tuxcare of mlflow. CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24.",
      "vulnerability": {
        "name": "CVE-2024-37061"
      },
      "impact_statement": "CVE-2024-37061 (MLproject code execution): no upstream fix exists \u2014 GHSA-pqcv-qw2r-r859 has no patched version and mlflow/mlflow#12257 (2024-06-05) is still open without maintainer response. The MLproject entry-point `command` is a shell string executed via `bash -c` by design (mlflow/projects/_project_spec.py:232, mlflow/projects/backend/local.py:274); running an untrusted MLproject is equivalent to running an untrusted script, and upstream master adds no validation to this path. Mitigation is operational (only run trusted projects), as communicated to Aikido on 2025-12-18 for mlflow 2.22.4 (PYELSCVE-436 Won't Fix). The bot's 'patches already applied via c8405983e' mapping was wrong: that commit is the CVE-2024-8859 registry path-traversal fix in mlflow/server/handlers.py, unrelated to Projects. Reviewed by esultanaliev 2026-09-24."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4263 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-4263"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6838 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-6838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8859 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2024-8859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-0453 does not affect version 2.9.1.post6+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-0453"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-11201"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1474 affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-1474"
      },
      "action_statement": "Vulnerability CVE-2025-1474 affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 does not affect version 2.9.1.post6+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.9.1.post6+tuxcare of mlflow. Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Upstream 3bf6d81a adds check_tarfile_security() and wires it into mlflow/pyfunc/dbconnect_artifact_cache.py, which does not exist on 2.9.1. There is no tar extraction path on the branch at all: every tarfile.open() in mlflow/ is a write (\"w:gz\" in sagemaker/__init__.py, \"w\" in file_utils.py) and both extractall() calls are zipfile, not tarfile. MR !54 carried only the helper and its tests, leaving dead code with no caller; it has been reverted."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.9.1.post6+tuxcare of mlflow. CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "CVE-2025-15379 names _install_model_dependencies_to_env() under env_manager=LOCAL, which reads dependency strings from the model's python_env.yaml and interpolates them into a shell command. That function, the LOCAL env-manager branch, and any python_env.yaml read are all absent from mlflow 2.9.1 - verified in the shipped artifact mlflow-2.9.1.post8+tuxcare pulled from Nexus, not only in the branch. Control on shipped 2.22.4.post7 finds the function twice and the LOCAL branch once, so the check detects the code where it exists. 2.9.1's container installs a hardcoded server dependency list (gunicorn[gevent], mlserver pins) rather than model-supplied metadata. The GitHub range '< 3.8.1' is over-broad; the advisory prose scopes the defect to 3.8.0. Separately noted for its own assessment: 2.9.1 does interpolate model-derived values into bash -c elsewhere in _install_pyfunc_deps (the conda env filename and the virtualenv activate command) - a different code path, not this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post6+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-52967"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.9.1.post6+tuxcare of mlflow. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.9.1.post6+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.9.1.post6+tuxcare of mlflow. code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "code_not_present \u2014 the webhook feature does not exist on mlflow 2.9.1. Upstream 64aa0ab7 fixes SSRF in mlflow/webhooks/delivery.py by adding MLFLOW_WEBHOOK_ALLOW_PRIVATE_IPS and an ipaddress/socket check. On tuxcare-current/2.9.1 there is no mlflow/webhooks/ package (0 tree entries), 0 occurrences of MLFLOW_WEBHOOK and no validate_webhook_url definition, so the vulnerable code is absent and nothing can be reached. The auto-generated backport MR !55 carried only tests (tests/utils/test_validation.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post6+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "impact_statement": "Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.9.1.post6+tuxcare of mlflow. code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "code_not_present \u2014 the FastAPI/Starlette authentication path does not exist on mlflow 2.9.1. Upstream bb62e773 adds _authenticate_fastapi_request, _get_require_authentication_validator and StarletteRequest handling to mlflow/server/auth/__init__.py. On tuxcare-current/2.9.1 that file contains 0 occurrences of StarletteRequest or fastapi and _authenticate_fastapi_request is defined nowhere in the tree; auth is dispatched Flask-only via BEFORE_REQUEST_VALIDATORS / app.before_request. The vulnerable code is absent. The auto-generated backport MR !57 carried only tests (tests/server/auth/test_auth.py) and no production change; it was rejected and closed. Verified against the branch on 2026-09-03."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.9.1.post6+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post6+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 affects version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "action_statement": "Vulnerability CVE-2026-33865 affects version 2.9.1.post6+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.9.1.post6+tuxcare of mlflow. Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Not applicable to 2.9.1: the vulnerable endpoint does not exist on this branch. CVE-2026-33866 is an authorization bypass on GET /ajax-api/2.0/mlflow/logged-models/<model_id>/artifacts/files, fixed upstream by PR #21708 by registering that route in LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS with validate_can_read_logged_model. tuxcare-current/2.9.1 has no LoggedModel API at all: grep over mlflow/**/*.py returns 0 hits for each of 'logged-models', 'LOGGED_MODEL_BEFORE_REQUEST_VALIDATORS', 'validate_can_read_logged_model' and 'artifacts/files', against 3 hits for the validator dict on upstream master (same grep, so the search is sound). The GHSA range 'introduced: 0 / fixed: 3.11.0rc0' is a blanket range, not a code-level assessment."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.9.1.post6+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.9.1.post6+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-64849 because the webhook feature does not exist in this version. The vulnerability concerns unauthenticated SSRF via the webhook test endpoint (`POST /api/2.0/mlflow/webhooks/{id}/test`) which bypasses SSRF guards through redirect following. Webhooks were introduced in MLflow 3.3.0, significantly later than the target version 2.9.1.post4+tuxcare. Exhaus..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.9.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.9.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.9.1.post6+tuxcare of mlflow, and is fixed in 2.9.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/orjson@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/orjson@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27454 is fixed in version 3.8.5.post2+tuxcare of orjson.",
      "vulnerability": {
        "name": "CVE-2024-27454"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/orjson@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/orjson@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67221 affects version 3.8.5.post2+tuxcare of orjson, and is fixed in 3.8.5.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67221"
      },
      "action_statement": "Vulnerability CVE-2025-67221 affects version 3.8.5.post2+tuxcare of orjson, and is fixed in 3.8.5.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post14+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post14+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post14+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post14+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post14+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post14+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post14+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post14+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post14+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post14+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post14+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post14+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post14+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post14+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post14+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post14+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post14+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post14+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.5.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post1+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post1+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post1+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post1+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post1+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post1+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post1+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post1+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-32681 affects version 2.25.1.post1+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-32681"
      },
      "action_statement": "Vulnerability CVE-2023-32681 affects version 2.25.1.post1+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-35195 affects version 2.25.1.post1+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-35195"
      },
      "action_statement": "Vulnerability CVE-2024-35195 affects version 2.25.1.post1+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47081 affects version 2.25.1.post1+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-47081"
      },
      "action_statement": "Vulnerability CVE-2024-47081 affects version 2.25.1.post1+tuxcare of requests, and is fixed in 2.25.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/requests@2.25.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/requests@2.25.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25645 affects version 2.25.1.post1+tuxcare of requests, and is fixed in 2.25.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25645"
      },
      "action_statement": "Vulnerability CVE-2026-25645 affects version 2.25.1.post1+tuxcare of requests, and is fixed in 2.25.1.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pymysql@0.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pymysql@0.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-36039 is fixed in version 0.10.1.post1+tuxcare of pymysql.",
      "vulnerability": {
        "name": "CVE-2024-36039"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 43.0.3.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 43.0.3.post2+tuxcare of cryptography, and is fixed in 43.0.3.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 43.0.3.post2+tuxcare of cryptography, and is fixed in 43.0.3.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 43.0.3.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 43.0.3.post2+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 43.0.3.post2+tuxcare of cryptography, and is fixed in 43.0.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 43.0.3.post2+tuxcare of cryptography, and is fixed in 43.0.3.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post2+tuxcare of cryptography, and is fixed in 43.0.3.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post2+tuxcare of cryptography, and is fixed in 43.0.3.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post1+tuxcare of mlflow-skinny. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post1+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post1+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      },
      "action_statement": "Vulnerability CVE-2025-14287 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "action_statement": "Vulnerability CVE-2025-15031 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post1+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post1+tuxcare of mlflow-skinny. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post1+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      },
      "action_statement": "Vulnerability CVE-2026-0596 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post1+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post1+tuxcare of mlflow-skinny."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      },
      "action_statement": "Vulnerability CVE-2026-2033 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post1+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "action_statement": "Vulnerability CVE-2026-2614 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      },
      "action_statement": "Vulnerability CVE-2026-2635 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post1+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post1+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post1+tuxcare of mlflow-skinny."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post1+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post1+tuxcare of mlflow-skinny. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post1+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      },
      "action_statement": "Vulnerability CVE-2026-4137 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post1+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post1+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10086 is fixed in version 2.11.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "AIKIDO-2024-10086"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10560 is fixed in version 2.11.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "AIKIDO-2024-10560"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22195 is fixed in version 2.11.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-22195"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34064 is fixed in version 2.11.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-34064"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56201 affects version 2.11.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-56201"
      },
      "action_statement": "Vulnerability CVE-2024-56201 affects version 2.11.3.post2+tuxcare of jinja2."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56326 is fixed in version 2.11.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2024-56326"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/jinja2@2.11.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27516 is fixed in version 2.11.3.post2+tuxcare of jinja2.",
      "vulnerability": {
        "name": "CVE-2025-27516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post8+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post8+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post8+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post8+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post8+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post8+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post8+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post8+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post7+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post7+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-53981"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24486 is fixed in version 0.0.6.post7+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-24486"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40347 is fixed in version 0.0.6.post7+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-40347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42561 is fixed in version 0.0.6.post7+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-42561"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53537 is fixed in version 0.0.6.post7+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-53537"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53538 is fixed in version 0.0.6.post7+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-53538"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53540 is fixed in version 0.0.6.post7+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-53540"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post11+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post11+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post11+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post11+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post11+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post11+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post11+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.5.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post11+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/httpx@0.22.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/httpx@0.22.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41945 is fixed in version 0.22.0.post1+tuxcare of httpx.",
      "vulnerability": {
        "name": "CVE-2021-41945"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@4.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@4.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6839 is fixed in version 4.0.2.post3+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6839"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@4.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@4.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6844 is fixed in version 4.0.2.post3+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6844"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask-cors@4.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask-cors@4.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6866 is fixed in version 4.0.2.post3+tuxcare of flask-cors.",
      "vulnerability": {
        "name": "CVE-2024-6866"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10085 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post2+tuxcare.",
      "vulnerability": {
        "name": "AIKIDO-2024-10085"
      },
      "action_statement": "Vulnerability AIKIDO-2024-10085 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10410 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post3+tuxcare.",
      "vulnerability": {
        "name": "AIKIDO-2024-10410"
      },
      "action_statement": "Vulnerability AIKIDO-2024-10410 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23934 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-23934"
      },
      "action_statement": "Vulnerability CVE-2023-23934 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-25577 is fixed in version 1.0.1.post1+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-25577"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46136 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46136"
      },
      "action_statement": "Vulnerability CVE-2023-46136 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      },
      "action_statement": "Vulnerability CVE-2024-34069 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 is fixed in version 1.0.1.post1+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 is fixed in version 1.0.1.post1+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      },
      "action_statement": "Vulnerability CVE-2025-66221 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      },
      "action_statement": "Vulnerability CVE-2026-21860 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      },
      "action_statement": "Vulnerability CVE-2026-27199 affects version 1.0.1.post1+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post10+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post10+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post10+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post10+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post10+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post10+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post10+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.5.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post10+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64439 is fixed in version 2.1.2.post1+tuxcare of langgraph-checkpoint.",
      "vulnerability": {
        "name": "CVE-2025-64439"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27794 affects version 2.1.2.post1+tuxcare of langgraph-checkpoint, and is fixed in 2.1.2.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27794"
      },
      "action_statement": "Vulnerability CVE-2026-27794 affects version 2.1.2.post1+tuxcare of langgraph-checkpoint, and is fixed in 2.1.2.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48775 affects version 2.1.2.post1+tuxcare of langgraph-checkpoint, and is fixed in 2.1.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48775"
      },
      "action_statement": "Vulnerability CVE-2026-48775 affects version 2.1.2.post1+tuxcare of langgraph-checkpoint, and is fixed in 2.1.2.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post10+tuxcare of mlflow. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post10+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post10+tuxcare of mlflow. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post10+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post10+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post10+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post10+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post10+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post10+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post10+tuxcare of mlflow. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post10+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post10+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm is fixed in version 2.22.4.post10+tuxcare of mlflow.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10085 is fixed in version 1.0.1.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10410 is fixed in version 1.0.1.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10410"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23934 is fixed in version 1.0.1.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-23934"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-25577 is fixed in version 1.0.1.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-25577"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46136 is fixed in version 1.0.1.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2023-46136"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 is fixed in version 1.0.1.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 is fixed in version 1.0.1.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 is fixed in version 1.0.1.post4+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 affects version 1.0.1.post4+tuxcare of werkzeug, and is fixed in 1.0.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      },
      "action_statement": "Vulnerability CVE-2025-66221 affects version 1.0.1.post4+tuxcare of werkzeug, and is fixed in 1.0.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 affects version 1.0.1.post4+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      },
      "action_statement": "Vulnerability CVE-2026-21860 affects version 1.0.1.post4+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 affects version 1.0.1.post4+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      },
      "action_statement": "Vulnerability CVE-2026-27199 affects version 1.0.1.post4+tuxcare of werkzeug, and is fixed in 1.0.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 42.0.8.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 42.0.8.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 42.0.8.post3+tuxcare of cryptography."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 42.0.8.post3+tuxcare of cryptography. not_affected \u2014 Target version 42.0.8.post2+tuxcare is NOT affected by CVE-2026-69248. The vulnerability requires wildcard DNS SAN support in name constraint validation, which was introduced in upstream commit 286c89128 (Jan 7, 2025) and fixed in commit 91d728897 (Mar 25, 2026, also known as CVE-2026-34073). The 42.x branch never received the vulnerable wildcard support code. Instead, this version uses the old...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 Target version 42.0.8.post2+tuxcare is NOT affected by CVE-2026-69248. The vulnerability requires wildcard DNS SAN support in name constraint validation, which was introduced in upstream commit 286c89128 (Jan 7, 2025) and fixed in commit 91d728897 (Mar 25, 2026, also known as CVE-2026-34073). The 42.x branch never received the vulnerable wildcard support code. Instead, this version uses the old..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 42.0.8.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 42.0.8.post3+tuxcare of cryptography, and is fixed in 42.0.8.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 42.0.8.post3+tuxcare of cryptography, and is fixed in 42.0.8.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 is fixed in version 75.8.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 affects version 75.8.0.post1+tuxcare of setuptools, and is fixed in 75.8.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      },
      "action_statement": "Vulnerability CVE-2026-59890 affects version 75.8.0.post1+tuxcare of setuptools, and is fixed in 75.8.0.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post8+tuxcare of mlflow. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post8+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post8+tuxcare of mlflow. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post8+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post8+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post8+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post8+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post8+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post8+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post8+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post8+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post8+tuxcare of mlflow. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post8+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post8+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 is fixed in version 2.22.4.post8+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post8+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post8+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 affects version 42.0.0.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      },
      "action_statement": "Vulnerability CVE-2024-0727 affects version 42.0.0.post2+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-28T09:32:48.362925+00:00",
      "status_notes": "Vulnerability CVE-2024-12797 is fixed in version 42.0.0.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-12797"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 42.0.0.post2+tuxcare of cryptography, and is fixed in 42.0.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 42.0.0.post2+tuxcare of cryptography, and is fixed in 42.0.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 42.0.0.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 42.0.0.post2+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 42.0.0.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 42.0.0.post2+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 42.0.0.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 42.0.0.post2+tuxcare of cryptography. not_affected \u2014 The target repository (cryptography 42.0.0.post1+tuxcare source code) is not affected by GHSA-537c-gmf6-5ccf. This CVE concerns vulnerable OpenSSL bundled in pre-built PyPI wheels, not the cryptography source code itself. The CVE explicitly excludes source builds from its scope, stating that sdist users are responsible for their own OpenSSL. The target is a source repository with no vendored Op...",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The target repository (cryptography 42.0.0.post1+tuxcare source code) is not affected by GHSA-537c-gmf6-5ccf. This CVE concerns vulnerable OpenSSL bundled in pre-built PyPI wheels, not the cryptography source code itself. The CVE explicitly excludes source builds from its scope, stating that sdist users are responsible for their own OpenSSL. The target is a source repository with no vendored Op..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 42.0.0.post2+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-h4gh-qq45-vh27"
      },
      "action_statement": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 42.0.0.post2+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 42.0.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 42.0.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 42.0.8.post4+tuxcare of cryptography."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 does not affect version 42.0.8.post4+tuxcare of cryptography. not_affected \u2014 Target version 42.0.8.post2+tuxcare is NOT affected by CVE-2026-69248. The vulnerability requires wildcard DNS SAN support in name constraint validation, which was introduced in upstream commit 286c89128 (Jan 7, 2025) and fixed in commit 91d728897 (Mar 25, 2026, also known as CVE-2026-34073). The 42.x branch never received the vulnerable wildcard support code. Instead, this version uses the old...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "impact_statement": "not_affected \u2014 Target version 42.0.8.post2+tuxcare is NOT affected by CVE-2026-69248. The vulnerability requires wildcard DNS SAN support in name constraint validation, which was introduced in upstream commit 286c89128 (Jan 7, 2025) and fixed in commit 91d728897 (Mar 25, 2026, also known as CVE-2026-34073). The 42.x branch never received the vulnerable wildcard support code. Instead, this version uses the old..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 42.0.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.8.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.8.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 42.0.8.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post7+tuxcare of mlflow. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post7+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post7+tuxcare of mlflow. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post7+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post7+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post7+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post7+tuxcare of mlflow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post7+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post7+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post7+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post7+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post7+tuxcare of mlflow. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post7+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post7+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post7+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post7+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post7+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post7+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post7+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post7+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post7+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post7+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post7+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post7+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post7+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post7+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post7+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33430 is fixed in version 1.15.4.post4+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-33430"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41495 is fixed in version 1.15.4.post4+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-41495"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.15.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.15.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-41496 affects version 1.15.4.post4+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-41496"
      },
      "action_statement": "Vulnerability CVE-2021-41496 affects version 1.15.4.post4+tuxcare of numpy."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.27.0.post9+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post9+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post9+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post9+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post9+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 is fixed in version 0.27.0.post9+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 is fixed in version 0.27.0.post9+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 is fixed in version 0.27.0.post9+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 is fixed in version 0.27.0.post9+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/scikit-learn@1.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/scikit-learn@1.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-5206 affects version 1.0.2.post1+tuxcare of scikit-learn, and is fixed in 1.0.2.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-5206"
      },
      "action_statement": "Vulnerability CVE-2024-5206 affects version 1.0.2.post1+tuxcare of scikit-learn, and is fixed in 1.0.2.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/idna@3.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/idna@3.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3651 is fixed in version 3.6.post1+tuxcare of idna.",
      "vulnerability": {
        "name": "CVE-2024-3651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/idna@3.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/idna@3.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45409 affects version 3.6.post1+tuxcare of idna, and is fixed in 3.6.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-45409"
      },
      "action_statement": "Vulnerability CVE-2026-45409 affects version 3.6.post1+tuxcare of idna, and is fixed in 3.6.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.27.0.post8+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post8+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post8+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post8+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post8+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 is fixed in version 0.27.0.post8+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 is fixed in version 0.27.0.post8+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 is fixed in version 0.27.0.post8+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.27.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.27.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 is fixed in version 0.27.0.post8+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 43.0.3.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 is fixed in version 43.0.3.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 43.0.3.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 43.0.3.post4+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 43.0.3.post4+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post4+tuxcare of cryptography, and is fixed in 43.0.3.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post4+tuxcare of cryptography, and is fixed in 43.0.3.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post3+tuxcare of mlflow-skinny. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post3+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post3+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post3+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post3+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post3+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post3+tuxcare of mlflow-skinny. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post3+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post3+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post3+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post3+tuxcare of mlflow-skinny."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post3+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post3+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post3+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post3+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post3+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post3+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post3+tuxcare of mlflow-skinny."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post3+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post3+tuxcare of mlflow-skinny. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post3+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      },
      "action_statement": "Vulnerability CVE-2026-4137 affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post3+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post3+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post1+tuxcare of mlflow. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      },
      "action_statement": "Vulnerability CVE-2025-14287 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      },
      "action_statement": "Vulnerability CVE-2025-15031 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post1+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post1+tuxcare of mlflow. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post1+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      },
      "action_statement": "Vulnerability CVE-2026-0596 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post1+tuxcare of mlflow."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      },
      "action_statement": "Vulnerability CVE-2026-2033 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post1+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      },
      "action_statement": "Vulnerability CVE-2026-2614 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      },
      "action_statement": "Vulnerability CVE-2026-2635 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post1+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post1+tuxcare of mlflow.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post1+tuxcare of mlflow."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post1+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post1+tuxcare of mlflow. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post1+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      },
      "action_statement": "Vulnerability CVE-2026-4137 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post1+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post1+tuxcare of mlflow, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pytest@7.4.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pytest@7.4.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-71176 is fixed in version 7.4.4.post1+tuxcare of pytest.",
      "vulnerability": {
        "name": "CVE-2025-71176"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 43.0.3.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 is fixed in version 43.0.3.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 43.0.3.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 43.0.3.post3+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 43.0.3.post3+tuxcare of cryptography, and is fixed in 43.0.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 43.0.3.post3+tuxcare of cryptography, and is fixed in 43.0.3.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post3+tuxcare of cryptography, and is fixed in 43.0.3.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post3+tuxcare of cryptography, and is fixed in 43.0.3.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/h11@0.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/h11@0.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-43859 is fixed in version 0.9.0.post1+tuxcare of h11.",
      "vulnerability": {
        "name": "CVE-2025-43859"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-20916 is fixed in version 9.0.0.post3+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2019-20916"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3572 is fixed in version 9.0.0.post3+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2021-3572"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-5752 is fixed in version 9.0.0.post3+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2023-5752"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-8869 is fixed in version 9.0.0.post3+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2025-8869"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-13346 is fixed in version 9.0.0.post3+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2026-13346"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1703 affects version 9.0.0.post3+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2026-1703"
      },
      "action_statement": "Vulnerability CVE-2026-1703 affects version 9.0.0.post3+tuxcare of pip."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3219 is fixed in version 9.0.0.post3+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2026-3219"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6357 is fixed in version 9.0.0.post3+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2026-6357"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pip@9.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pip@9.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8643 is fixed in version 9.0.0.post3+tuxcare of pip.",
      "vulnerability": {
        "name": "CVE-2026-8643"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T13:12:52.268351+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.5.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.5.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post12+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.5.post2+tuxcare of aiohttp. aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.5 has no aiohttp/_cookie_helpers.py; BaseRequest.cookies uses stdlib SimpleCookie and performs no per-cookie logging, so the log-flooding path fixed by upstream 64629a08 does not exist on this branch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 does not affect version 3.8.5.post2+tuxcare of aiohttp. aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "impact_statement": "aiohttp 3.8.5 already carries an equivalent guard that predates this CVE: StaticResource._handle does Path(rel_url) and raises HTTPForbidden when filename.anchor is set, before self._directory.joinpath() and therefore before any resolve(). Path.anchor and Path.is_absolute() agree on every relevant input (//remote/share, /absolute/path, D:\\path, relative names), so the control blocks exactly what the upstream fix 0ae2aa076c84 blocks; only the status differs (403 vs 404). The CVE applies to 3.8.6 because a backport had removed that check there - restored in MR !140. No code change is needed on 3.8.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.5.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.5.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.5.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.5.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.5.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.5.post2+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post2+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post2+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.5.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.5.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.5.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.5.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.5.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.5.post2+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post2+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post2+tuxcare of aiohttp, and is fixed in 3.8.5.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37059 does not affect version 2.22.4.post4+tuxcare of mlflow-skinny. already_fixed \u2014 fix already present in target (commit c6c9002f29)",
      "vulnerability": {
        "name": "CVE-2024-37059"
      },
      "impact_statement": "already_fixed \u2014 fix already present in target (commit c6c9002f29)"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-10279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14279"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-14287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2025-15031"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post4+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15036"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15379 does not affect version 2.22.4.post4+tuxcare of mlflow-skinny. Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')",
      "vulnerability": {
        "name": "CVE-2025-15379"
      },
      "impact_statement": "Patches already applied: a22ce7157f646bdce4c95106fc38ccc9ca289205 (already in target via 3e7233561c 'PYELSCVE-466: Fix for AIKIDO-2025-11008')"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:45:05.079328+00:00",
      "status_notes": "Vulnerability CVE-2025-15381 affects version 2.22.4.post4+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-15381"
      },
      "action_statement": "Vulnerability CVE-2025-15381 affects version 2.22.4.post4+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post4+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0545"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-0596"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10803 affects version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-10803"
      },
      "action_statement": "Vulnerability CVE-2026-10803 affects version 2.22.4.post4+tuxcare of mlflow-skinny."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post4+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2393"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2635"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2651 affects version 2.22.4.post4+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-2651"
      },
      "action_statement": "Vulnerability CVE-2026-2651 affects version 2.22.4.post4+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post4+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2652"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2734 affects version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-2734"
      },
      "action_statement": "Vulnerability CVE-2026-2734 affects version 2.22.4.post4+tuxcare of mlflow-skinny."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post4+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-3198"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33865 does not affect version 2.22.4.post4+tuxcare of mlflow-skinny. Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33865"
      },
      "impact_statement": "Frontend-only vulnerability; the TuxCare build ships no web UI. CVE-2026-33865 lives entirely in the MLflow JavaScript frontend (yaml.load -> yaml.safeLoad in ShowArtifactLoggedModelView.tsx and useValidateLoggedModelSignature.ts). Verified on the shipped artifact mlflow-2.22.4.post9+tuxcare-py3-none-any.whl (release pipeline 104717): 670 files, zero entries under mlflow/server/js/, no js/build directory, 6.0 MB against 27.7 MB for the upstream PyPI wheel of the same version. mlflow/server/__init__.py sets static_folder=\"js/build\" and guards on index.html existing, so the REST API is served and the UI page is absent. The vulnerable code is not present in what customers install."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post4+tuxcare of mlflow-skinny. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33866"
      },
      "impact_statement": "Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4035 affects version 2.22.4.post4+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4035"
      },
      "action_statement": "Vulnerability CVE-2026-4035 affects version 2.22.4.post4+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post4+tuxcare of mlflow-skinny.",
      "vulnerability": {
        "name": "CVE-2026-4137"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-64849 does not affect version 2.22.4.post4+tuxcare of mlflow-skinny. not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-64849"
      },
      "impact_statement": "not_affected \u2014 MLflow version 2.22.4 does not contain the webhooks feature that is vulnerable to CVE-2026-64849. The webhooks functionality (including the webhook URL validation, HTTP delivery mechanism, and the `/api/2.0/mlflow/webhooks/{id}/test` endpoint) was introduced in version 3.4.0, which is significantly later than the target version 2.22.4. Without the webhooks feature, the SSRF vulnerability descri..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8147 affects version 2.22.4.post4+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8147"
      },
      "action_statement": "Vulnerability CVE-2026-8147 affects version 2.22.4.post4+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/mlflow-skinny@2.22.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post4+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gqvg-gmmx-x4hm"
      },
      "action_statement": "Vulnerability GHSA-gqvg-gmmx-x4hm affects version 2.22.4.post4+tuxcare of mlflow-skinny, and is fixed in 2.22.4.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/protobuf@4.24.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/protobuf@4.24.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0994 affects version 4.24.3.post1+tuxcare of protobuf, and is fixed in 4.24.3.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-0994"
      },
      "action_statement": "Vulnerability CVE-2026-0994 affects version 4.24.3.post1+tuxcare of protobuf, and is fixed in 4.24.3.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-0727 affects version 42.0.0.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-0727"
      },
      "action_statement": "Vulnerability CVE-2024-0727 affects version 42.0.0.post3+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-28T09:32:48.362925+00:00",
      "status_notes": "Vulnerability CVE-2024-12797 is fixed in version 42.0.0.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2024-12797"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 42.0.0.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 42.0.0.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 42.0.0.post3+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 42.0.0.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 42.0.0.post3+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 is fixed in version 42.0.0.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 42.0.0.post3+tuxcare of cryptography. not_affected \u2014 The target repository (cryptography 42.0.0.post1+tuxcare source code) is not affected by GHSA-537c-gmf6-5ccf. This CVE concerns vulnerable OpenSSL bundled in pre-built PyPI wheels, not the cryptography source code itself. The CVE explicitly excludes source builds from its scope, stating that sdist users are responsible for their own OpenSSL. The target is a source repository with no vendored Op...",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "impact_statement": "not_affected \u2014 The target repository (cryptography 42.0.0.post1+tuxcare source code) is not affected by GHSA-537c-gmf6-5ccf. This CVE concerns vulnerable OpenSSL bundled in pre-built PyPI wheels, not the cryptography source code itself. The CVE explicitly excludes source builds from its scope, stating that sdist users are responsible for their own OpenSSL. The target is a source repository with no vendored Op..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@42.0.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@42.0.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 42.0.0.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-h4gh-qq45-vh27"
      },
      "action_statement": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 42.0.0.post3+tuxcare of cryptography."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29159 is fixed in version 0.25.0.post1+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2023-29159"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47874 is fixed in version 0.25.0.post1+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2024-47874"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54121 is fixed in version 0.25.0.post1+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2025-54121"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62727 does not affect version 0.25.0.post1+tuxcare of starlette. CVE-2025-62727 is a Range header parsing flaw in FileResponse. That parsing was introduced upstream in starlette 0.39.0; version 0.25.0 predates it. Verified on tuxcare-current/0.25.0: the string \"Range\" does not occur anywhere in the starlette package, and FileResponse implements no range handling. Same disposition and same reasoning as starlette 0.27.0 (VPV 81209), which is already not_affected with justification code_not_present.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62727"
      },
      "impact_statement": "CVE-2025-62727 is a Range header parsing flaw in FileResponse. That parsing was introduced upstream in starlette 0.39.0; version 0.25.0 predates it. Verified on tuxcare-current/0.25.0: the string \"Range\" does not occur anywhere in the starlette package, and FileResponse implements no range handling. Same disposition and same reasoning as starlette 0.27.0 (VPV 81209), which is already not_affected with justification code_not_present."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48710 is fixed in version 0.25.0.post1+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48710"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48817 is fixed in version 0.25.0.post1+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48818 is fixed in version 0.25.0.post1+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-48818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54282 is fixed in version 0.25.0.post1+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54282"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/starlette@0.25.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/starlette@0.25.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54283 is fixed in version 0.25.0.post1+tuxcare of starlette.",
      "vulnerability": {
        "name": "CVE-2026-54283"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-jose@3.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-jose@3.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-33663 is fixed in version 3.3.0.post2+tuxcare of python-jose.",
      "vulnerability": {
        "name": "CVE-2024-33663"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-jose@3.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-jose@3.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-33664 is fixed in version 3.3.0.post2+tuxcare of python-jose.",
      "vulnerability": {
        "name": "CVE-2024-33664"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@1.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@1.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-30861 is fixed in version 1.1.4.post3+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2023-30861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/flask@1.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/flask@1.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27205 is fixed in version 1.1.4.post3+tuxcare of flask.",
      "vulnerability": {
        "name": "CVE-2026-27205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@22.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@22.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10216 is fixed in version 22.0.0.post1+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "AIKIDO-2024-10216"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gunicorn@22.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gunicorn@22.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6827 is fixed in version 22.0.0.post1+tuxcare of gunicorn.",
      "vulnerability": {
        "name": "CVE-2024-6827"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 is fixed in version 2.3.8.post2+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 affects version 2.3.8.post2+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      },
      "action_statement": "Vulnerability CVE-2024-49766 affects version 2.3.8.post2+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 affects version 2.3.8.post2+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      },
      "action_statement": "Vulnerability CVE-2024-49767 affects version 2.3.8.post2+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 is fixed in version 2.3.8.post2+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 affects version 2.3.8.post2+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      },
      "action_statement": "Vulnerability CVE-2026-21860 affects version 2.3.8.post2+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 affects version 2.3.8.post2+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      },
      "action_statement": "Vulnerability CVE-2026-27199 affects version 2.3.8.post2+tuxcare of werkzeug, and is fixed in 2.3.8.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10085 is fixed in version 2.2.3.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10410 is fixed in version 2.2.3.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "AIKIDO-2024-10410"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46136 affects version 2.2.3.post3+tuxcare of werkzeug, and is fixed in 2.2.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46136"
      },
      "action_statement": "Vulnerability CVE-2023-46136 affects version 2.2.3.post3+tuxcare of werkzeug, and is fixed in 2.2.3.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34069 affects version 2.2.3.post3+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-34069"
      },
      "action_statement": "Vulnerability CVE-2024-34069 affects version 2.2.3.post3+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49766 is fixed in version 2.2.3.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-49767 is fixed in version 2.2.3.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2024-49767"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66221 affects version 2.2.3.post3+tuxcare of werkzeug.",
      "vulnerability": {
        "name": "CVE-2025-66221"
      },
      "action_statement": "Vulnerability CVE-2025-66221 affects version 2.2.3.post3+tuxcare of werkzeug."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21860 affects version 2.2.3.post3+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21860"
      },
      "action_statement": "Vulnerability CVE-2026-21860 affects version 2.2.3.post3+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27199 affects version 2.2.3.post3+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27199"
      },
      "action_statement": "Vulnerability CVE-2026-27199 affects version 2.2.3.post3+tuxcare of werkzeug, and is fixed in 2.2.3.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tqdm@4.66.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tqdm@4.66.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34062 is fixed in version 4.66.1.post1+tuxcare of tqdm.",
      "vulnerability": {
        "name": "CVE-2024-34062"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/deepdiff@6.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/deepdiff@6.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58367 is fixed in version 6.2.3.post1+tuxcare of deepdiff.",
      "vulnerability": {
        "name": "CVE-2025-58367"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/deepdiff@6.2.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/deepdiff@6.2.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33155 affects version 6.2.3.post1+tuxcare of deepdiff, and is fixed in 6.2.3.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33155"
      },
      "action_statement": "Vulnerability CVE-2026-33155 affects version 6.2.3.post1+tuxcare of deepdiff, and is fixed in 6.2.3.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/numpy@1.21.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/numpy@1.21.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-34141 is fixed in version 1.21.0.post1+tuxcare of numpy.",
      "vulnerability": {
        "name": "CVE-2021-34141"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/apache-airflow-providers-http@4.13.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/apache-airflow-providers-http@4.13.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69219 is fixed in version 4.13.3.post1+tuxcare of apache-airflow-providers-http.",
      "vulnerability": {
        "name": "CVE-2025-69219"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.63.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.63.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-32677 is fixed in version 0.63.0.post3+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2021-32677"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.63.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.63.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.63.0.post3+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-21712 is fixed in version 20.3.0.post4+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2022-21712"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-24801 affects version 20.3.0.post4+tuxcare of twisted, and is fixed in 20.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-24801"
      },
      "action_statement": "Vulnerability CVE-2022-24801 affects version 20.3.0.post4+tuxcare of twisted, and is fixed in 20.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-39348 affects version 20.3.0.post4+tuxcare of twisted, and is fixed in 20.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-39348"
      },
      "action_statement": "Vulnerability CVE-2022-39348 affects version 20.3.0.post4+tuxcare of twisted, and is fixed in 20.3.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46137 is fixed in version 20.3.0.post4+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2023-46137"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41671 is fixed in version 20.3.0.post4+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2024-41671"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41810 is fixed in version 20.3.0.post4+tuxcare of twisted.",
      "vulnerability": {
        "name": "CVE-2024-41810"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/twisted@20.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42304 affects version 20.3.0.post4+tuxcare of twisted, and is fixed in 20.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42304"
      },
      "action_statement": "Vulnerability CVE-2026-42304 affects version 20.3.0.post4+tuxcare of twisted, and is fixed in 20.3.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 44.0.3.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 is fixed in version 44.0.3.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 affects version 44.0.3.post3+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      },
      "action_statement": "Vulnerability CVE-2026-69247 affects version 44.0.3.post3+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 is fixed in version 44.0.3.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 44.0.3.post3+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 44.0.3.post3+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 44.0.3.post3+tuxcare of cryptography.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 is fixed in version 44.0.3.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 44.0.3.post1+tuxcare of cryptography, and is fixed in 44.0.3.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 44.0.3.post1+tuxcare of cryptography, and is fixed in 44.0.3.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69247 affects version 44.0.3.post1+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69247"
      },
      "action_statement": "Vulnerability CVE-2026-69247 affects version 44.0.3.post1+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 44.0.3.post1+tuxcare of cryptography, and is fixed in 44.0.3.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 44.0.3.post1+tuxcare of cryptography, and is fixed in 44.0.3.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 44.0.3.post1+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 44.0.3.post1+tuxcare of cryptography, and is fixed in 44.0.3.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@44.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 44.0.3.post1+tuxcare of cryptography, and is fixed in 44.0.3.post2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 44.0.3.post1+tuxcare of cryptography, and is fixed in 44.0.3.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/deepdiff@6.2.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/deepdiff@6.2.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58367 is fixed in version 6.2.3.post2+tuxcare of deepdiff.",
      "vulnerability": {
        "name": "CVE-2025-58367"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/deepdiff@6.2.3.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/deepdiff@6.2.3.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33155 is fixed in version 6.2.3.post2+tuxcare of deepdiff.",
      "vulnerability": {
        "name": "CVE-2026-33155"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dnspython@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dnspython@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29483 is fixed in version 2.3.0.post2+tuxcare of dnspython.",
      "vulnerability": {
        "name": "CVE-2023-29483"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/orjson@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/orjson@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27454 affects version 3.8.5.post1+tuxcare of orjson, and is fixed in 3.8.5.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27454"
      },
      "action_statement": "Vulnerability CVE-2024-27454 affects version 3.8.5.post1+tuxcare of orjson, and is fixed in 3.8.5.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/orjson@3.8.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/orjson@3.8.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67221 affects version 3.8.5.post1+tuxcare of orjson, and is fixed in 3.8.5.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67221"
      },
      "action_statement": "Vulnerability CVE-2025-67221 affects version 3.8.5.post1+tuxcare of orjson, and is fixed in 3.8.5.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/fastapi@0.104.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/fastapi@0.104.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.104.1.post1+tuxcare of fastapi.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26007 affects version 43.0.3.post1+tuxcare of cryptography, and is fixed in 43.0.3.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-26007"
      },
      "action_statement": "Vulnerability CVE-2026-26007 affects version 43.0.3.post1+tuxcare of cryptography, and is fixed in 43.0.3.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34073 affects version 43.0.3.post1+tuxcare of cryptography, and is fixed in 43.0.3.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34073"
      },
      "action_statement": "Vulnerability CVE-2026-34073 affects version 43.0.3.post1+tuxcare of cryptography, and is fixed in 43.0.3.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69248 affects version 43.0.3.post1+tuxcare of cryptography.",
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "action_statement": "Vulnerability CVE-2026-69248 affects version 43.0.3.post1+tuxcare of cryptography."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69249 affects version 43.0.3.post1+tuxcare of cryptography, and is fixed in 43.0.3.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "action_statement": "Vulnerability CVE-2026-69249 affects version 43.0.3.post1+tuxcare of cryptography, and is fixed in 43.0.3.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/cryptography@43.0.3.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post1+tuxcare of cryptography, and is fixed in 43.0.3.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-537c-gmf6-5ccf"
      },
      "action_statement": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post1+tuxcare of cryptography, and is fixed in 43.0.3.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post5+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-24762"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post5+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2024-53981"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24486 affects version 0.0.6.post5+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24486"
      },
      "action_statement": "Vulnerability CVE-2026-24486 affects version 0.0.6.post5+tuxcare of python-multipart, and is fixed in 0.0.6.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40347 is fixed in version 0.0.6.post5+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-40347"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42561 affects version 0.0.6.post5+tuxcare of python-multipart, and is fixed in 0.0.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42561"
      },
      "action_statement": "Vulnerability CVE-2026-42561 affects version 0.0.6.post5+tuxcare of python-multipart, and is fixed in 0.0.6.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53537 is fixed in version 0.0.6.post5+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-53537"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53538 is fixed in version 0.0.6.post5+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-53538"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53540 is fixed in version 0.0.6.post5+tuxcare of python-multipart.",
      "vulnerability": {
        "name": "CVE-2026-53540"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post6+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post6+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post6+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post6+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post6+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post6+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.4.post6+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post6+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post6+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post4+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post4+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post4+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post4+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "action_statement": "Vulnerability CVE-2026-54280 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.4.post4+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post4+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post4+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post13+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post13+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post13+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post13+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post13+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post13+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post13+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post13+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post13+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post13+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post12+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post12+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post12+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post12+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post12+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post12+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post12+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post12+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post12+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post12+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post12+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post12+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 11.3.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 affects version 11.3.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      },
      "action_statement": "Vulnerability CVE-2026-42309 affects version 11.3.0.post2+tuxcare of pillow."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 11.3.0.post2+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post8+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.4.post8+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.4.post8+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post8+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.4.post8+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.4.post8+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post8+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post8+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post8+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post8+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post8+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post8+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.4.post8+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.4.post8+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post8+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post8+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post8+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post8+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post8+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post8+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/lightgbm@3.3.5.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/lightgbm@3.3.5.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T11:11:04.521924+00:00",
      "status_notes": "Vulnerability CVE-2024-43598 is fixed in version 3.3.5.post1+tuxcare of lightgbm.",
      "vulnerability": {
        "name": "CVE-2024-43598"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post2+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post2+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post2+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post2+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "action_statement": "Vulnerability CVE-2026-54280 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.4.post2+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post2+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post2+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post5+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post5+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post5+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post5+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post5+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.4.post5+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post5+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post5+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post1+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post1+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post1+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post1+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "action_statement": "Vulnerability CVE-2026-54280 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.4.post1+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post1+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post1+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post11+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post11+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post11+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post11+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post11+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post11+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post11+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post11+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post11+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post11+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post11+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post11+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post11+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post11+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post9+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.4.post9+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.4.post9+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post9+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post9+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post9+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post9+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post9+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post9+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post9+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.4.post9+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.4.post9+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post9+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post9+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post9+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post9+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post9+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post9+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 affects version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      },
      "action_statement": "Vulnerability CVE-2026-42309 affects version 11.3.0.post5+tuxcare of pillow."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 11.3.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post1+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      },
      "action_statement": "Vulnerability CVE-2026-40192 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 affects version 11.3.0.post1+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      },
      "action_statement": "Vulnerability CVE-2026-42309 affects version 11.3.0.post1+tuxcare of pillow."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 11.3.0.post1+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post3+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post3+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post3+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post3+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "action_statement": "Vulnerability CVE-2026-54280 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.4.post3+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post3+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post3+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post10+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.4.post10+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.4.post10+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post10+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post10+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post10+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post10+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post10+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post10+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post10+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post10+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post10+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post10+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post10+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post10+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post10+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 11.3.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 affects version 11.3.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      },
      "action_statement": "Vulnerability CVE-2026-42309 affects version 11.3.0.post4+tuxcare of pillow."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 is fixed in version 11.3.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 11.3.0.post4+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 11.3.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42309 affects version 11.3.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42309"
      },
      "action_statement": "Vulnerability CVE-2026-42309 affects version 11.3.0.post3+tuxcare of pillow."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 11.3.0.post3+tuxcare of pillow, and is fixed in 11.3.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 affects version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      },
      "action_statement": "Vulnerability CVE-2023-47627 affects version 3.8.4.post7+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.4.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.4.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.4.post7+tuxcare of aiohttp. aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp/_cookie_helpers.py and its per-cookie internal_logger.warning() first exist in aiohttp 3.12.7 (OSV GIT range introduced 80bb38fa). On tuxcare-current/3.8.4 BaseRequest.cookies is stdlib SimpleCookie, which drops invalid cookies silently and logs nothing: an attack request with 3000 illegal cookie names produces 0 log records on this branch. Same disposition as VPV 18638 (3.8.5, MR !138 closed 2026-09-15). MR !146 rejected and closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:31:07.524695+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.4.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.4.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.4.post7+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post7+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post7+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.4.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.4.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.4.post7+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54280"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.4.post7+tuxcare of aiohttp, and is fixed in 3.8.4.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post7+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post7+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 10.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 10.4.0.post4+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:45:00.428333+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 10.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 10.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 10.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 is fixed in version 10.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 10.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 is fixed in version 10.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 10.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 10.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 10.4.0.post7+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 10.4.0.post10+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 10.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 is fixed in version 10.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 10.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 is fixed in version 10.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 10.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 10.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 10.4.0.post6+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 10.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 10.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 10.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 10.4.0.post5+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post1+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      },
      "action_statement": "Vulnerability CVE-2026-40192 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 10.4.0.post1+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 10.4.0.post3+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 10.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 10.4.0.post8+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-25990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-40192"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42311 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42311"
      },
      "action_statement": "Vulnerability CVE-2026-42311 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54059 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54059"
      },
      "action_statement": "Vulnerability CVE-2026-54059 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55379 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55379"
      },
      "action_statement": "Vulnerability CVE-2026-55379 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:46:00.278398+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 10.4.0.post2+tuxcare of pillow, and is fixed in 10.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      },
      "action_statement": "Vulnerability CVE-2023-44271 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post1+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post1+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      },
      "action_statement": "Vulnerability CVE-2024-28219 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.5.0.post1+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post7+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post7+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post7+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post7+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.6.post7+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post8+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post8+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post8+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post8+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.6.post8+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post3+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post3+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post3+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post3+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.6.post3+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post12+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post12+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post12+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post12+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post12+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post12+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post12+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post12+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post12+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post12+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 9.5.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.5.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.5.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 9.5.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.5.0.post5+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 9.5.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.5.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.5.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 9.5.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 9.5.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 9.5.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post4+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post4+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post4+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post4+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.6.post4+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:15:08.978693+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:15:08.978693+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:15:08.978693+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:15:08.978693+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:15:08.978693+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:15:08.978693+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:15:08.978693+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:15:08.978693+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:15:08.978693+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:15:08.978693+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 9.5.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post5+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post5+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post5+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post5+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.6.post5+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post10+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post10+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post10+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post10+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post10+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      },
      "action_statement": "Vulnerability CVE-2023-44271 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.5.0.post2+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post14+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post14+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post14+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post14+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post1+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post1+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post1+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post1+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.6.post1+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post6+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post6+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post6+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post6+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.6.post6+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.5.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.5.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 9.5.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.5.0.post4+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post9+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post9+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post9+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post9+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post9+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.5.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.5.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T08:40:40.287998+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T13:19:07.423599+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.5.0.post3+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post11+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post11+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post11+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post11+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post11+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post11+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post11+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post11+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post11+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post11+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post11+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post11+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:51:00.078045+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:50:00.203197+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 9.5.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post13+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post13+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post13+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post13+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post13+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post13+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post2+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "impact_statement": "aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628)."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post2+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post2+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post2+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "action_statement": "Vulnerability CVE-2026-69244 affects version 3.8.6.post2+tuxcare of aiohttp, and is fixed in 3.8.6.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22815 is fixed in version 8.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22816 is fixed in version 8.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22816"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-45198"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post6+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
      "vulnerability": {
        "name": "CVE-2023-4863"
      },
      "impact_statement": "not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 8.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 8.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 8.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 8.4.0.post6+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4fx9-vc88-q2xc is fixed in version 8.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-4fx9-vc88-q2xc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 9.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 9.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.4.0.post7+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-56pw-mpj4-fxww"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.3.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.3.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:05:45.406697+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 affects version 75.3.2.post1+tuxcare of setuptools, and is fixed in 75.3.2.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      },
      "action_statement": "Vulnerability CVE-2025-47273 affects version 75.3.2.post1+tuxcare of setuptools, and is fixed in 75.3.2.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.3.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.3.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 is fixed in version 75.3.2.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post10+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post10+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post10+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post10+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post10+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post10+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post10+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post10+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post10+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post10+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:02:26.630643+00:00",
      "status_notes": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post9+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-56pw-mpj4-fxww"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      },
      "action_statement": "Vulnerability CVE-2023-37276 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post3+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post3+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post3+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post3+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post3+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post3+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post3+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post3+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post3+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:45:09.719878+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:45:09.719878+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:45:09.719878+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:45:09.719878+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:45:09.719878+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:45:09.719878+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:45:09.719878+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:45:09.719878+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:45:09.719878+00:00",
      "status_notes": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-56pw-mpj4-fxww"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post15+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post15+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post15+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post15+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post15+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post15+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post15+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post15+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post15+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post15+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post15+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post15+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post15+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:17:00.175527+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post15+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      },
      "action_statement": "Vulnerability CVE-2023-44271 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.4.0.post3+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-56pw-mpj4-fxww"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      },
      "action_statement": "Vulnerability CVE-2023-44271 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      },
      "action_statement": "Vulnerability CVE-2023-4863 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      },
      "action_statement": "Vulnerability CVE-2023-50447 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      },
      "action_statement": "Vulnerability CVE-2024-28219 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-56pw-mpj4-fxww affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-56pw-mpj4-fxww"
      },
      "action_statement": "Vulnerability GHSA-56pw-mpj4-fxww affects version 9.4.0.post1+tuxcare of pillow, and is fixed in 9.4.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.4.0.post4+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-56pw-mpj4-fxww"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2022-22815 is fixed in version 8.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2022-22816 is fixed in version 8.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22816"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-45198"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post7+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
      "vulnerability": {
        "name": "CVE-2023-4863"
      },
      "impact_statement": "not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 8.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 8.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 8.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 8.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 8.4.0.post7+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-4fx9-vc88-q2xc is fixed in version 8.4.0.post7+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-4fx9-vc88-q2xc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 is fixed in version 75.0.0.post2+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.0.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.0.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:26:00.226980+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 is fixed in version 75.0.0.post2+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22815 is fixed in version 8.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22816 is fixed in version 8.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22816"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-45198"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post5+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
      "vulnerability": {
        "name": "CVE-2023-4863"
      },
      "impact_statement": "not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 8.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 8.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 8.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4fx9-vc88-q2xc"
      },
      "action_statement": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post5+tuxcare of pillow, and is fixed in 8.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      },
      "action_statement": "Vulnerability CVE-2023-37276 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post4+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post4+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post4+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post4+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post4+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post4+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post4+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post4+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post4+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post11+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post11+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post11+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post11+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post11+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post11+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post11+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post11+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post11+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post11+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post14+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post14+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post14+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post14+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post14+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post14+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post14+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post14+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post14+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post14+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post14+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post14+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post14+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post14+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post14+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post14+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post14+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post14+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post13+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post13+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post13+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post13+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post13+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post13+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post13+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post13+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post13+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post13+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post13+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post13+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post13+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post13+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post13+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post12+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post12+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post12+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post12+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post12+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post12+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post12+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post12+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post12+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post12+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.3.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.3.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:05:45.406697+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 is fixed in version 75.3.2.post2+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.3.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.3.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:05:45.406697+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 is fixed in version 75.3.2.post2+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2022-22815 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2022-22816 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22816"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-45198"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post8+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
      "vulnerability": {
        "name": "CVE-2023-4863"
      },
      "impact_statement": "not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability GHSA-4fx9-vc88-q2xc is fixed in version 8.4.0.post8+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-4fx9-vc88-q2xc"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22815 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22815"
      },
      "action_statement": "Vulnerability CVE-2022-22815 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22816 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22816"
      },
      "action_statement": "Vulnerability CVE-2022-22816 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-45198"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post3+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
      "vulnerability": {
        "name": "CVE-2023-4863"
      },
      "impact_statement": "not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      },
      "action_statement": "Vulnerability CVE-2024-28219 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 8.4.0.post3+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4fx9-vc88-q2xc"
      },
      "action_statement": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post3+tuxcare of pillow, and is fixed in 8.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      },
      "action_statement": "Vulnerability CVE-2023-37276 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      },
      "action_statement": "Vulnerability CVE-2023-49081 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post1+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post1+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post1+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post1+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post1+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post1+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post1+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post1+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post1+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      },
      "action_statement": "Vulnerability CVE-2023-37276 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      },
      "action_statement": "Vulnerability CVE-2024-23829 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      },
      "action_statement": "Vulnerability CVE-2024-30251 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      },
      "action_statement": "Vulnerability CVE-2025-53643 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post2+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post2+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post2+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post2+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post2+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post2+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post2+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post2+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post2+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22815 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22815"
      },
      "action_statement": "Vulnerability CVE-2022-22815 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22816 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22816"
      },
      "action_statement": "Vulnerability CVE-2022-22816 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post1+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post1+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-45198"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post1+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
      "vulnerability": {
        "name": "CVE-2023-4863"
      },
      "impact_statement": "not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post1+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      },
      "action_statement": "Vulnerability CVE-2024-28219 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4fx9-vc88-q2xc"
      },
      "action_statement": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post1+tuxcare of pillow, and is fixed in 8.4.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post8+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post8+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post8+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post8+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post8+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post8+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post8+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post8+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post8+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      },
      "action_statement": "Vulnerability CVE-2023-49082 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      },
      "action_statement": "Vulnerability CVE-2024-27306 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post5+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post5+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post5+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post5+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post5+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post5+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post5+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post5+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post5+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.4.0.post5+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post5+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-56pw-mpj4-fxww"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      },
      "action_statement": "Vulnerability CVE-2023-44271 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      },
      "action_statement": "Vulnerability CVE-2024-28219 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      },
      "action_statement": "Vulnerability CVE-2026-54058 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.4.0.post2+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-56pw-mpj4-fxww"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-44271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-4863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 is fixed in version 9.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54058 is fixed in version 9.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54058"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 9.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 9.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:06:12.222328+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:48:00.091308+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 9.4.0.post6+tuxcare of pillow, and is fixed in 9.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@9.4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@9.4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post6+tuxcare of pillow.",
      "vulnerability": {
        "name": "GHSA-56pw-mpj4-fxww"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post9+tuxcare of aiohttp."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post9+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post9+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post9+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post9+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post9+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post9+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post9+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post9+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post9+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      },
      "action_statement": "Vulnerability CVE-2024-23334 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      },
      "action_statement": "Vulnerability CVE-2024-52304 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post6+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post6+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post6+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post6+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post6+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post6+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post6+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post6+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      },
      "action_statement": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post6+tuxcare of aiohttp, and is fixed in 3.8.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post7+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post7+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post7+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post7+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22815 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22815"
      },
      "action_statement": "Vulnerability CVE-2022-22815 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22816 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22816"
      },
      "action_statement": "Vulnerability CVE-2022-22816 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-45198"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post2+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
      "vulnerability": {
        "name": "CVE-2023-4863"
      },
      "impact_statement": "not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post2+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      },
      "action_statement": "Vulnerability CVE-2024-28219 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      },
      "action_statement": "Vulnerability CVE-2026-54060 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      },
      "action_statement": "Vulnerability CVE-2026-55798 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4fx9-vc88-q2xc"
      },
      "action_statement": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post2+tuxcare of pillow, and is fixed in 8.4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22815 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22815"
      },
      "action_statement": "Vulnerability CVE-2022-22815 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22816 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22816"
      },
      "action_statement": "Vulnerability CVE-2022-22816 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-22817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2022-45198"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post4+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
      "vulnerability": {
        "name": "CVE-2023-4863"
      },
      "impact_statement": "not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2023-50447"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28219 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-28219"
      },
      "action_statement": "Vulnerability CVE-2024-28219 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-42308 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42308"
      },
      "action_statement": "Vulnerability CVE-2026-42308 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-42310 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42310"
      },
      "action_statement": "Vulnerability CVE-2026-42310 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54060 is fixed in version 8.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-54060"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-55380 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55380"
      },
      "action_statement": "Vulnerability CVE-2026-55380 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55798 is fixed in version 8.4.0.post4+tuxcare of pillow.",
      "vulnerability": {
        "name": "CVE-2026-55798"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59197 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59197"
      },
      "action_statement": "Vulnerability CVE-2026-59197 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59198 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59198"
      },
      "action_statement": "Vulnerability CVE-2026-59198 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59199 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59199"
      },
      "action_statement": "Vulnerability CVE-2026-59199 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59200 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59200"
      },
      "action_statement": "Vulnerability CVE-2026-59200 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59204 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59204"
      },
      "action_statement": "Vulnerability CVE-2026-59204 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T07:51:42.012949+00:00",
      "status_notes": "Vulnerability CVE-2026-59205 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59205"
      },
      "action_statement": "Vulnerability CVE-2026-59205 affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4fx9-vc88-q2xc"
      },
      "action_statement": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post4+tuxcare of pillow, and is fixed in 8.4.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47273 is fixed in version 75.0.0.post1+tuxcare of setuptools.",
      "vulnerability": {
        "name": "CVE-2025-47273"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/setuptools@75.0.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/setuptools@75.0.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:26:00.226980+00:00",
      "status_notes": "Vulnerability CVE-2026-59890 affects version 75.0.0.post1+tuxcare of setuptools, and is fixed in 75.0.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59890"
      },
      "action_statement": "Vulnerability CVE-2026-59890 affects version 75.0.0.post1+tuxcare of setuptools, and is fixed in 75.0.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29217 is fixed in version 2.3.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2022-29217"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:19:00.139552+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.3.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.3.0.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.3.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.3.0.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:23:00.154863+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.3.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.3.0.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.3.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.3.0.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.3.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.3.0.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.3.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.3.0.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 affects version 2.3.0.post2+tuxcare of pyjwt, and is fixed in 2.3.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      },
      "action_statement": "Vulnerability CVE-2026-32597 affects version 2.3.0.post2+tuxcare of pyjwt, and is fixed in 2.3.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 affects version 2.3.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "action_statement": "Vulnerability CVE-2026-48522 affects version 2.3.0.post2+tuxcare of pyjwt."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 does not affect version 2.3.0.post2+tuxcare of pyjwt. not_affected \u2014 Target PyJWT version 2.3.0 is not affected by CVE-2026-48524. The vulnerability requires the jwk_set_cache feature with a finally-block cache-clearing pattern that was introduced in version 2.5.0. Version 2.3.0 predates this feature and uses a simpler lru_cache-based architecture that inherently avoids the cache-clearing behavior.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "impact_statement": "not_affected \u2014 Target PyJWT version 2.3.0 is not affected by CVE-2026-48524. The vulnerability requires the jwk_set_cache feature with a finally-block cache-clearing pattern that was introduced in version 2.5.0. Version 2.3.0 predates this feature and uses a simpler lru_cache-based architecture that inherently avoids the cache-clearing behavior."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 does not affect version 2.3.0.post2+tuxcare of pyjwt. not_affected \u2014 Version 2.3.0.post1+tuxcare does not support RFC 7797 detached payloads (b64=false feature), which is the attack vector for CVE-2026-48525. The vulnerability-specific code path does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "impact_statement": "not_affected \u2014 Version 2.3.0.post1+tuxcare does not support RFC 7797 detached payloads (b64=false feature), which is the attack vector for CVE-2026-48525. The vulnerability-specific code path does not exist in this version."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 2.3.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 affects version 1.26.4.post3+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      },
      "action_statement": "Vulnerability CVE-2021-33503 affects version 1.26.4.post3+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 affects version 1.26.4.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      },
      "action_statement": "Vulnerability CVE-2023-43804 affects version 1.26.4.post3+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.26.4.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 is fixed in version 1.26.4.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 affects version 1.26.4.post3+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      },
      "action_statement": "Vulnerability CVE-2025-50181 affects version 1.26.4.post3+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.26.4.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 is fixed in version 1.26.4.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.26.4.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.26.4.post3+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.26.4.post3+tuxcare of urllib3, and is fixed in 1.26.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.26.4.post3+tuxcare of urllib3, and is fixed in 1.26.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 1.26.4.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 1.26.4.post3+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.26.4.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.26.4.post3+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29217 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-29217"
      },
      "action_statement": "Vulnerability CVE-2022-29217 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T00:27:05.135813+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 does not affect version 1.7.1.post2+tuxcare of pyjwt. not_affected \u2014 PyJWT 1.7.1 is not affected by CVE-2026-101917. The vulnerability concerns PyJWKClient's unbounded JWKS endpoint refresh mechanism triggered by unknown key IDs, enabling unauthenticated DoS attacks. PyJWT version 1.7.1 predates the introduction of the PyJWKClient class entirely - the jwt/jwks_client.py module does not exist, and there is no JWKS endpoint fetching functionality. While this versi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "impact_statement": "not_affected \u2014 PyJWT 1.7.1 is not affected by CVE-2026-101917. The vulnerability concerns PyJWKClient's unbounded JWKS endpoint refresh mechanism triggered by unknown key IDs, enabling unauthenticated DoS attacks. PyJWT version 1.7.1 predates the introduction of the PyJWKClient class entirely - the jwt/jwks_client.py module does not exist, and there is no JWKS endpoint fetching functionality. While this versi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T01:08:30.473565+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 does not affect version 1.7.1.post2+tuxcare of pyjwt. not_affected \u2014 PyJWT 1.7.1.post3+tuxcare is not affected by CVE-2026-102267. The vulnerability affects the PyJWKClient class in jwt/jwks_client.py, which fetches JWKS over HTTP and incorrectly follows redirects. This feature does not exist in version 1.7.1 - the PyJWKClient class and jwt/jwks_client.py module were introduced in later versions of PyJWT (after 1.7.1). The target version lacks any HTTP client fu...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "impact_statement": "not_affected \u2014 PyJWT 1.7.1.post3+tuxcare is not affected by CVE-2026-102267. The vulnerability affects the PyJWKClient class in jwt/jwks_client.py, which fetches JWKS over HTTP and incorrectly follows redirects. This feature does not exist in version 1.7.1 - the PyJWKClient class and jwt/jwks_client.py module were introduced in later versions of PyJWT (after 1.7.1). The target version lacks any HTTP client fu..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 1.7.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 1.7.1.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 1.7.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 1.7.1.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 1.7.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 1.7.1.post2+tuxcare of pyjwt."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 is fixed in version 1.7.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 1.7.1.post2+tuxcare of pyjwt. not_affected \u2014 Version 1.7.1 is not affected by CVE-2026-48522. The vulnerability concerns PyJWKClient accepting non-HTTP(S) URL schemes (file://, ftp://, data:) without validation, enabling local file read and SSRF. However, PyJWKClient class does not exist in version 1.7.1 - it was introduced in later versions (tested vulnerable in 2.11.0 and 2.12.1). The affected component and its entire remote JWKS fetchi...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "not_affected \u2014 Version 1.7.1 is not affected by CVE-2026-48522. The vulnerability concerns PyJWKClient accepting non-HTTP(S) URL schemes (file://, ftp://, data:) without validation, enabling local file read and SSRF. However, PyJWKClient class does not exist in version 1.7.1 - it was introduced in later versions (tested vulnerable in 2.11.0 and 2.12.1). The affected component and its entire remote JWKS fetchi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 does not affect version 1.7.1.post2+tuxcare of pyjwt. not_affected \u2014 PyJWT version 1.7.1 is not affected by CVE-2026-48524. The vulnerability concerns PyJWKClient.fetch_data() clearing the JWKS cache on fetch errors, enabling unlimited HTTP requests. PyJWKClient was introduced in PyJWT 2.0.0 (2021), and this target version 1.7.1 (2018) predates that feature entirely. No JWKS fetching capability, no cache mechanism, and no code path exists for the vulnerability p...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "impact_statement": "not_affected \u2014 PyJWT version 1.7.1 is not affected by CVE-2026-48524. The vulnerability concerns PyJWKClient.fetch_data() clearing the JWKS cache on fetch errors, enabling unlimited HTTP requests. PyJWKClient was introduced in PyJWT 2.0.0 (2021), and this target version 1.7.1 (2018) predates that feature entirely. No JWKS fetching capability, no cache mechanism, and no code path exists for the vulnerability p..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:30:18.436677+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "action_statement": "Vulnerability CVE-2026-48525 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      },
      "action_statement": "Vulnerability CVE-2026-48526 affects version 1.7.1.post2+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29217 affects version 1.7.1.post1+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-29217"
      },
      "action_statement": "Vulnerability CVE-2022-29217 affects version 1.7.1.post1+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T00:27:05.135813+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 does not affect version 1.7.1.post1+tuxcare of pyjwt. not_affected \u2014 PyJWT 1.7.1 is not affected by CVE-2026-101917. The vulnerability concerns PyJWKClient's unbounded JWKS endpoint refresh mechanism triggered by unknown key IDs, enabling unauthenticated DoS attacks. PyJWT version 1.7.1 predates the introduction of the PyJWKClient class entirely - the jwt/jwks_client.py module does not exist, and there is no JWKS endpoint fetching functionality. While this versi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "impact_statement": "not_affected \u2014 PyJWT 1.7.1 is not affected by CVE-2026-101917. The vulnerability concerns PyJWKClient's unbounded JWKS endpoint refresh mechanism triggered by unknown key IDs, enabling unauthenticated DoS attacks. PyJWT version 1.7.1 predates the introduction of the PyJWKClient class entirely - the jwt/jwks_client.py module does not exist, and there is no JWKS endpoint fetching functionality. While this versi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T01:08:30.473565+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 does not affect version 1.7.1.post1+tuxcare of pyjwt. not_affected \u2014 PyJWT 1.7.1.post3+tuxcare is not affected by CVE-2026-102267. The vulnerability affects the PyJWKClient class in jwt/jwks_client.py, which fetches JWKS over HTTP and incorrectly follows redirects. This feature does not exist in version 1.7.1 - the PyJWKClient class and jwt/jwks_client.py module were introduced in later versions of PyJWT (after 1.7.1). The target version lacks any HTTP client fu...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "impact_statement": "not_affected \u2014 PyJWT 1.7.1.post3+tuxcare is not affected by CVE-2026-102267. The vulnerability affects the PyJWKClient class in jwt/jwks_client.py, which fetches JWKS over HTTP and incorrectly follows redirects. This feature does not exist in version 1.7.1 - the PyJWKClient class and jwt/jwks_client.py module were introduced in later versions of PyJWT (after 1.7.1). The target version lacks any HTTP client fu..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 1.7.1.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 1.7.1.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 1.7.1.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 1.7.1.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 1.7.1.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 1.7.1.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 affects version 1.7.1.post1+tuxcare of pyjwt, and is fixed in 1.7.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      },
      "action_statement": "Vulnerability CVE-2026-32597 affects version 1.7.1.post1+tuxcare of pyjwt, and is fixed in 1.7.1.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 1.7.1.post1+tuxcare of pyjwt. not_affected \u2014 Version 1.7.1 is not affected by CVE-2026-48522. The vulnerability concerns PyJWKClient accepting non-HTTP(S) URL schemes (file://, ftp://, data:) without validation, enabling local file read and SSRF. However, PyJWKClient class does not exist in version 1.7.1 - it was introduced in later versions (tested vulnerable in 2.11.0 and 2.12.1). The affected component and its entire remote JWKS fetchi...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "not_affected \u2014 Version 1.7.1 is not affected by CVE-2026-48522. The vulnerability concerns PyJWKClient accepting non-HTTP(S) URL schemes (file://, ftp://, data:) without validation, enabling local file read and SSRF. However, PyJWKClient class does not exist in version 1.7.1 - it was introduced in later versions (tested vulnerable in 2.11.0 and 2.12.1). The affected component and its entire remote JWKS fetchi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 does not affect version 1.7.1.post1+tuxcare of pyjwt. not_affected \u2014 PyJWT version 1.7.1 is not affected by CVE-2026-48524. The vulnerability concerns PyJWKClient.fetch_data() clearing the JWKS cache on fetch errors, enabling unlimited HTTP requests. PyJWKClient was introduced in PyJWT 2.0.0 (2021), and this target version 1.7.1 (2018) predates that feature entirely. No JWKS fetching capability, no cache mechanism, and no code path exists for the vulnerability p...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "impact_statement": "not_affected \u2014 PyJWT version 1.7.1 is not affected by CVE-2026-48524. The vulnerability concerns PyJWKClient.fetch_data() clearing the JWKS cache on fetch errors, enabling unlimited HTTP requests. PyJWKClient was introduced in PyJWT 2.0.0 (2021), and this target version 1.7.1 (2018) predates that feature entirely. No JWKS fetching capability, no cache mechanism, and no code path exists for the vulnerability p..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:30:18.436677+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 affects version 1.7.1.post1+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "action_statement": "Vulnerability CVE-2026-48525 affects version 1.7.1.post1+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 affects version 1.7.1.post1+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      },
      "action_statement": "Vulnerability CVE-2026-48526 affects version 1.7.1.post1+tuxcare of pyjwt, and is fixed in 1.7.1.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post7+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 is fixed in version 1.25.11.post7+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post7+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 is fixed in version 1.25.11.post7+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.25.11.post7+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.25.11.post7+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 is fixed in version 1.25.11.post7+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.25.11.post7+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.25.11.post7+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 is fixed in version 1.25.11.post7+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.25.11.post7+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.25.11.post7+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 is fixed in version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 affects version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      },
      "action_statement": "Vulnerability CVE-2023-43804 affects version 1.26.4.post5+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 is fixed in version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 is fixed in version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.26.4.post5+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 is fixed in version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 1.26.4.post5+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.26.4.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.26.4.post5+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post6+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 is fixed in version 1.25.11.post6+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post6+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 is fixed in version 1.25.11.post6+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.25.11.post6+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.25.11.post6+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 affects version 1.25.11.post6+tuxcare of urllib3, and is fixed in 1.25.11.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      },
      "action_statement": "Vulnerability CVE-2025-66471 affects version 1.25.11.post6+tuxcare of urllib3, and is fixed in 1.25.11.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.25.11.post6+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.25.11.post6+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 is fixed in version 1.25.11.post6+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.25.11.post6+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.25.11.post6+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29217 is fixed in version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2022-29217"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:19:00.139552+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:23:00.154863+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 affects version 2.3.0.post1+tuxcare of pyjwt, and is fixed in 2.3.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      },
      "action_statement": "Vulnerability CVE-2026-32597 affects version 2.3.0.post1+tuxcare of pyjwt, and is fixed in 2.3.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 affects version 2.3.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "action_statement": "Vulnerability CVE-2026-48522 affects version 2.3.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 does not affect version 2.3.0.post1+tuxcare of pyjwt. not_affected \u2014 Target PyJWT version 2.3.0 is not affected by CVE-2026-48524. The vulnerability requires the jwk_set_cache feature with a finally-block cache-clearing pattern that was introduced in version 2.5.0. Version 2.3.0 predates this feature and uses a simpler lru_cache-based architecture that inherently avoids the cache-clearing behavior.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "impact_statement": "not_affected \u2014 Target PyJWT version 2.3.0 is not affected by CVE-2026-48524. The vulnerability requires the jwk_set_cache feature with a finally-block cache-clearing pattern that was introduced in version 2.5.0. Version 2.3.0 predates this feature and uses a simpler lru_cache-based architecture that inherently avoids the cache-clearing behavior."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 does not affect version 2.3.0.post1+tuxcare of pyjwt. not_affected \u2014 Version 2.3.0.post1+tuxcare does not support RFC 7797 detached payloads (b64=false feature), which is the attack vector for CVE-2026-48525. The vulnerability-specific code path does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "impact_statement": "not_affected \u2014 Version 2.3.0.post1+tuxcare does not support RFC 7797 detached payloads (b64=false feature), which is the attack vector for CVE-2026-48525. The vulnerability-specific code path does not exist in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 affects version 2.3.0.post1+tuxcare of pyjwt, and is fixed in 2.3.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      },
      "action_statement": "Vulnerability CVE-2026-48526 affects version 2.3.0.post1+tuxcare of pyjwt, and is fixed in 2.3.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 is fixed in version 1.26.4.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 affects version 1.26.4.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      },
      "action_statement": "Vulnerability CVE-2023-43804 affects version 1.26.4.post4+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.26.4.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 is fixed in version 1.26.4.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.26.4.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.26.4.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 is fixed in version 1.26.4.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.26.4.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.26.4.post4+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.26.4.post4+tuxcare of urllib3, and is fixed in 1.26.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.26.4.post4+tuxcare of urllib3, and is fixed in 1.26.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 1.26.4.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 1.26.4.post4+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.26.4.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.26.4.post4+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      },
      "action_statement": "Vulnerability CVE-2023-43804 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      },
      "action_statement": "Vulnerability CVE-2024-37891 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      },
      "action_statement": "Vulnerability CVE-2025-50181 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      },
      "action_statement": "Vulnerability CVE-2025-66418 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      },
      "action_statement": "Vulnerability CVE-2025-66471 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.25.11.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.25.11.post2+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.25.11.post2+tuxcare of urllib3, and is fixed in 1.25.11.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.25.11.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.25.11.post2+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 affects version 1.25.11.post3+tuxcare of urllib3, and is fixed in 1.25.11.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      },
      "action_statement": "Vulnerability CVE-2023-43804 affects version 1.25.11.post3+tuxcare of urllib3, and is fixed in 1.25.11.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 affects version 1.25.11.post3+tuxcare of urllib3, and is fixed in 1.25.11.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      },
      "action_statement": "Vulnerability CVE-2024-37891 affects version 1.25.11.post3+tuxcare of urllib3, and is fixed in 1.25.11.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.25.11.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.25.11.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 affects version 1.25.11.post3+tuxcare of urllib3, and is fixed in 1.25.11.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      },
      "action_statement": "Vulnerability CVE-2025-66471 affects version 1.25.11.post3+tuxcare of urllib3, and is fixed in 1.25.11.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.25.11.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.25.11.post3+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.25.11.post3+tuxcare of urllib3, and is fixed in 1.25.11.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.25.11.post3+tuxcare of urllib3, and is fixed in 1.25.11.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.25.11.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.25.11.post3+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 is fixed in version 1.25.11.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 affects version 1.25.11.post4+tuxcare of urllib3, and is fixed in 1.25.11.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      },
      "action_statement": "Vulnerability CVE-2024-37891 affects version 1.25.11.post4+tuxcare of urllib3, and is fixed in 1.25.11.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.25.11.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.25.11.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 affects version 1.25.11.post4+tuxcare of urllib3, and is fixed in 1.25.11.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      },
      "action_statement": "Vulnerability CVE-2025-66471 affects version 1.25.11.post4+tuxcare of urllib3, and is fixed in 1.25.11.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.25.11.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.25.11.post4+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.25.11.post4+tuxcare of urllib3, and is fixed in 1.25.11.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.25.11.post4+tuxcare of urllib3, and is fixed in 1.25.11.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.25.11.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.25.11.post4+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 affects version 1.26.4.post2+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      },
      "action_statement": "Vulnerability CVE-2021-33503 affects version 1.26.4.post2+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 affects version 1.26.4.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      },
      "action_statement": "Vulnerability CVE-2023-43804 affects version 1.26.4.post2+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.26.4.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 is fixed in version 1.26.4.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 affects version 1.26.4.post2+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      },
      "action_statement": "Vulnerability CVE-2025-50181 affects version 1.26.4.post2+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 affects version 1.26.4.post2+tuxcare of urllib3, and is fixed in 1.26.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      },
      "action_statement": "Vulnerability CVE-2025-66418 affects version 1.26.4.post2+tuxcare of urllib3, and is fixed in 1.26.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 affects version 1.26.4.post2+tuxcare of urllib3, and is fixed in 1.26.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      },
      "action_statement": "Vulnerability CVE-2025-66471 affects version 1.26.4.post2+tuxcare of urllib3, and is fixed in 1.26.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.26.4.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.26.4.post2+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.26.4.post2+tuxcare of urllib3, and is fixed in 1.26.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.26.4.post2+tuxcare of urllib3, and is fixed in 1.26.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 1.26.4.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 1.26.4.post2+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.26.4.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.26.4.post2+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      },
      "action_statement": "Vulnerability CVE-2021-33503 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 affects version 1.26.4.post1+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      },
      "action_statement": "Vulnerability CVE-2023-43804 affects version 1.26.4.post1+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.26.4.post1+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      },
      "action_statement": "Vulnerability CVE-2024-37891 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      },
      "action_statement": "Vulnerability CVE-2025-50181 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      },
      "action_statement": "Vulnerability CVE-2025-66418 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      },
      "action_statement": "Vulnerability CVE-2025-66471 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.26.4.post1+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.26.4.post1+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.26.4.post1+tuxcare of urllib3, and is fixed in 1.26.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 1.26.4.post1+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 1.26.4.post1+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.26.4.post1+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.26.4.post1+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29217 is fixed in version 2.3.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2022-29217"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:19:00.139552+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.3.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.3.0.post3+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.3.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.3.0.post3+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:23:00.154863+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.3.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.3.0.post3+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.3.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.3.0.post3+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.3.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.3.0.post3+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.3.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.3.0.post3+tuxcare of pyjwt."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 is fixed in version 2.3.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 affects version 2.3.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "action_statement": "Vulnerability CVE-2026-48522 affects version 2.3.0.post3+tuxcare of pyjwt."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 does not affect version 2.3.0.post3+tuxcare of pyjwt. not_affected \u2014 Target PyJWT version 2.3.0 is not affected by CVE-2026-48524. The vulnerability requires the jwk_set_cache feature with a finally-block cache-clearing pattern that was introduced in version 2.5.0. Version 2.3.0 predates this feature and uses a simpler lru_cache-based architecture that inherently avoids the cache-clearing behavior.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "impact_statement": "not_affected \u2014 Target PyJWT version 2.3.0 is not affected by CVE-2026-48524. The vulnerability requires the jwk_set_cache feature with a finally-block cache-clearing pattern that was introduced in version 2.5.0. Version 2.3.0 predates this feature and uses a simpler lru_cache-based architecture that inherently avoids the cache-clearing behavior."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 does not affect version 2.3.0.post3+tuxcare of pyjwt. not_affected \u2014 Version 2.3.0.post1+tuxcare does not support RFC 7797 detached payloads (b64=false feature), which is the attack vector for CVE-2026-48525. The vulnerability-specific code path does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "impact_statement": "not_affected \u2014 Version 2.3.0.post1+tuxcare does not support RFC 7797 detached payloads (b64=false feature), which is the attack vector for CVE-2026-48525. The vulnerability-specific code path does not exist in this version."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 2.3.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2021-33503"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43804 is fixed in version 1.25.11.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-43804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2023-45803"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 is fixed in version 1.25.11.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.25.11.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.25.11.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 affects version 1.25.11.post5+tuxcare of urllib3, and is fixed in 1.25.11.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      },
      "action_statement": "Vulnerability CVE-2025-66471 affects version 1.25.11.post5+tuxcare of urllib3, and is fixed in 1.25.11.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.25.11.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.25.11.post5+tuxcare of urllib3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.25.11.post5+tuxcare of urllib3, and is fixed in 1.25.11.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.25.11.post5+tuxcare of urllib3, and is fixed in 1.25.11.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.25.11.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.25.11.post5+tuxcare of urllib3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29217 is fixed in version 1.7.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2022-29217"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T00:27:05.135813+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 does not affect version 1.7.1.post3+tuxcare of pyjwt. not_affected \u2014 PyJWT 1.7.1 is not affected by CVE-2026-101917. The vulnerability concerns PyJWKClient's unbounded JWKS endpoint refresh mechanism triggered by unknown key IDs, enabling unauthenticated DoS attacks. PyJWT version 1.7.1 predates the introduction of the PyJWKClient class entirely - the jwt/jwks_client.py module does not exist, and there is no JWKS endpoint fetching functionality. While this versi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "impact_statement": "not_affected \u2014 PyJWT 1.7.1 is not affected by CVE-2026-101917. The vulnerability concerns PyJWKClient's unbounded JWKS endpoint refresh mechanism triggered by unknown key IDs, enabling unauthenticated DoS attacks. PyJWT version 1.7.1 predates the introduction of the PyJWKClient class entirely - the jwt/jwks_client.py module does not exist, and there is no JWKS endpoint fetching functionality. While this versi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T01:08:30.473565+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 does not affect version 1.7.1.post3+tuxcare of pyjwt. not_affected \u2014 PyJWT 1.7.1.post3+tuxcare is not affected by CVE-2026-102267. The vulnerability affects the PyJWKClient class in jwt/jwks_client.py, which fetches JWKS over HTTP and incorrectly follows redirects. This feature does not exist in version 1.7.1 - the PyJWKClient class and jwt/jwks_client.py module were introduced in later versions of PyJWT (after 1.7.1). The target version lacks any HTTP client fu...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "impact_statement": "not_affected \u2014 PyJWT 1.7.1.post3+tuxcare is not affected by CVE-2026-102267. The vulnerability affects the PyJWKClient class in jwt/jwks_client.py, which fetches JWKS over HTTP and incorrectly follows redirects. This feature does not exist in version 1.7.1 - the PyJWKClient class and jwt/jwks_client.py module were introduced in later versions of PyJWT (after 1.7.1). The target version lacks any HTTP client fu..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 1.7.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 1.7.1.post3+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T23:24:00.176349+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 1.7.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 1.7.1.post3+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T14:56:54.506693+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 1.7.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 1.7.1.post3+tuxcare of pyjwt."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 is fixed in version 1.7.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 1.7.1.post3+tuxcare of pyjwt. not_affected \u2014 Version 1.7.1 is not affected by CVE-2026-48522. The vulnerability concerns PyJWKClient accepting non-HTTP(S) URL schemes (file://, ftp://, data:) without validation, enabling local file read and SSRF. However, PyJWKClient class does not exist in version 1.7.1 - it was introduced in later versions (tested vulnerable in 2.11.0 and 2.12.1). The affected component and its entire remote JWKS fetchi...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "not_affected \u2014 Version 1.7.1 is not affected by CVE-2026-48522. The vulnerability concerns PyJWKClient accepting non-HTTP(S) URL schemes (file://, ftp://, data:) without validation, enabling local file read and SSRF. However, PyJWKClient class does not exist in version 1.7.1 - it was introduced in later versions (tested vulnerable in 2.11.0 and 2.12.1). The affected component and its entire remote JWKS fetchi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 does not affect version 1.7.1.post3+tuxcare of pyjwt. not_affected \u2014 PyJWT version 1.7.1 is not affected by CVE-2026-48524. The vulnerability concerns PyJWKClient.fetch_data() clearing the JWKS cache on fetch errors, enabling unlimited HTTP requests. PyJWKClient was introduced in PyJWT 2.0.0 (2021), and this target version 1.7.1 (2018) predates that feature entirely. No JWKS fetching capability, no cache mechanism, and no code path exists for the vulnerability p...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "impact_statement": "not_affected \u2014 PyJWT version 1.7.1 is not affected by CVE-2026-48524. The vulnerability concerns PyJWKClient.fetch_data() clearing the JWKS cache on fetch errors, enabling unlimited HTTP requests. PyJWKClient was introduced in PyJWT 2.0.0 (2021), and this target version 1.7.1 (2018) predates that feature entirely. No JWKS fetching capability, no cache mechanism, and no code path exists for the vulnerability p..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:30:18.436677+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 is fixed in version 1.7.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@1.7.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 1.7.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      },
      "action_statement": "Vulnerability CVE-2026-25673 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      },
      "action_statement": "Vulnerability CVE-2026-25674 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      },
      "action_statement": "Vulnerability CVE-2026-33033 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      },
      "action_statement": "Vulnerability CVE-2026-3902 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      },
      "action_statement": "Vulnerability CVE-2026-4292 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post4+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.2.post4+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      },
      "action_statement": "Vulnerability CVE-2021-45115 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      },
      "action_statement": "Vulnerability CVE-2021-45452 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      },
      "action_statement": "Vulnerability CVE-2022-22818 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      },
      "action_statement": "Vulnerability CVE-2022-23833 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      },
      "action_statement": "Vulnerability CVE-2022-28346 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      },
      "action_statement": "Vulnerability CVE-2022-28347 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      },
      "action_statement": "Vulnerability CVE-2022-34265 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      },
      "action_statement": "Vulnerability CVE-2022-36359 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      },
      "action_statement": "Vulnerability CVE-2023-31047 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      },
      "action_statement": "Vulnerability CVE-2023-36053 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      },
      "action_statement": "Vulnerability CVE-2023-43665 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post2+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post2+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post11+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post11+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post11+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post11+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post11+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post11+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post11+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post11+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post11+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post11+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post11+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 4.2.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post10+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post10+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post10+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post10+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      },
      "action_statement": "Vulnerability CVE-2026-25673 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      },
      "action_statement": "Vulnerability CVE-2026-3902 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post7+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.2.post7+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      },
      "action_statement": "Vulnerability CVE-2023-36053 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post8+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post8+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      },
      "action_statement": "Vulnerability CVE-2022-22818 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      },
      "action_statement": "Vulnerability CVE-2022-23833 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      },
      "action_statement": "Vulnerability CVE-2023-31047 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      },
      "action_statement": "Vulnerability CVE-2023-36053 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      },
      "action_statement": "Vulnerability CVE-2023-43665 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post4+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post4+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post14+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post14+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post14+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post14+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      },
      "action_statement": "Vulnerability CVE-2023-31047 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      },
      "action_statement": "Vulnerability CVE-2023-36053 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post7+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post7+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post10+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post10+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post10+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.2.post10+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      },
      "action_statement": "Vulnerability CVE-2026-25673 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      },
      "action_statement": "Vulnerability CVE-2026-25674 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      },
      "action_statement": "Vulnerability CVE-2026-33033 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      },
      "action_statement": "Vulnerability CVE-2026-33034 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      },
      "action_statement": "Vulnerability CVE-2026-3902 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      },
      "action_statement": "Vulnerability CVE-2026-4277 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      },
      "action_statement": "Vulnerability CVE-2026-4292 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post1+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.2.post1+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post11+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post11+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post11+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post11+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      },
      "action_statement": "Vulnerability CVE-2026-25673 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      },
      "action_statement": "Vulnerability CVE-2026-25674 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      },
      "action_statement": "Vulnerability CVE-2026-3902 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      },
      "action_statement": "Vulnerability CVE-2026-4292 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post5+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.2.post5+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post16+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post16+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post16+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post16+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post12+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post12+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post12+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post12+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post12+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post12+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post12+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 4.2.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post13+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post13+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post13+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post13+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post17+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post17+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post17+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post17+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post17+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post9+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post9+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post9+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.2.post9+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post20+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post20+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post20+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post20+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post20+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post20+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post20+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post20+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post20+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post20+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post20+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 4.0.post20+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post13+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post13+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post13+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 4.2.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      },
      "action_statement": "Vulnerability CVE-2026-25673 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      },
      "action_statement": "Vulnerability CVE-2026-25674 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      },
      "action_statement": "Vulnerability CVE-2026-3902 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post6+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.2.post6+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      },
      "action_statement": "Vulnerability CVE-2021-45115 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      },
      "action_statement": "Vulnerability CVE-2021-45116 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      },
      "action_statement": "Vulnerability CVE-2021-45452 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      },
      "action_statement": "Vulnerability CVE-2022-22818 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      },
      "action_statement": "Vulnerability CVE-2022-23833 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      },
      "action_statement": "Vulnerability CVE-2022-28346 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      },
      "action_statement": "Vulnerability CVE-2022-28347 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      },
      "action_statement": "Vulnerability CVE-2022-34265 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      },
      "action_statement": "Vulnerability CVE-2022-36359 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      },
      "action_statement": "Vulnerability CVE-2022-41323 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      },
      "action_statement": "Vulnerability CVE-2023-31047 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      },
      "action_statement": "Vulnerability CVE-2023-36053 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      },
      "action_statement": "Vulnerability CVE-2023-43665 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post1+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post1+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post21+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post21+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post21+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post21+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post21+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post21+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post21+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post21+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post21+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 4.0.post21+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      },
      "action_statement": "Vulnerability CVE-2026-25673 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      },
      "action_statement": "Vulnerability CVE-2026-25674 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      },
      "action_statement": "Vulnerability CVE-2026-33033 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      },
      "action_statement": "Vulnerability CVE-2026-3902 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      },
      "action_statement": "Vulnerability CVE-2026-4292 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post3+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.2.post3+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post12+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post12+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post12+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post12+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post22+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post22+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post22+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post22+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post22+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 4.0.post22+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post19+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post19+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post19+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post19+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post19+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post19+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post19+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post19+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post19+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post19+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post19+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post19+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post19+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 4.0.post19+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      },
      "action_statement": "Vulnerability CVE-2021-45115 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      },
      "action_statement": "Vulnerability CVE-2021-45452 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      },
      "action_statement": "Vulnerability CVE-2022-22818 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      },
      "action_statement": "Vulnerability CVE-2022-23833 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      },
      "action_statement": "Vulnerability CVE-2022-28346 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      },
      "action_statement": "Vulnerability CVE-2023-31047 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      },
      "action_statement": "Vulnerability CVE-2023-36053 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      },
      "action_statement": "Vulnerability CVE-2023-43665 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post3+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post3+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post18+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post18+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post18+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post18+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post18+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post18+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post18+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post18+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post18+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post18+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post18+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post18+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post18+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 4.0.post18+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      },
      "action_statement": "Vulnerability CVE-2023-31047 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      },
      "action_statement": "Vulnerability CVE-2023-36053 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      },
      "action_statement": "Vulnerability CVE-2023-43665 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post6+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post6+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      },
      "action_statement": "Vulnerability CVE-2026-25673 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      },
      "action_statement": "Vulnerability CVE-2026-3902 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post8+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.2.post8+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      },
      "action_statement": "Vulnerability CVE-2022-23833 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      },
      "action_statement": "Vulnerability CVE-2023-31047 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      },
      "action_statement": "Vulnerability CVE-2023-36053 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      },
      "action_statement": "Vulnerability CVE-2023-43665 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post5+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post5+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      },
      "action_statement": "Vulnerability CVE-2023-46695 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post9+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post9+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post9+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post9+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.2.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.2.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.2.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.2.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25673 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25673"
      },
      "action_statement": "Vulnerability CVE-2026-25673 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25674 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25674"
      },
      "action_statement": "Vulnerability CVE-2026-25674 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33033 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33033"
      },
      "action_statement": "Vulnerability CVE-2026-33033 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33034 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33034"
      },
      "action_statement": "Vulnerability CVE-2026-33034 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3902 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-3902"
      },
      "action_statement": "Vulnerability CVE-2026-3902 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4277 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4277"
      },
      "action_statement": "Vulnerability CVE-2026-4277 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4292 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4292"
      },
      "action_statement": "Vulnerability CVE-2026-4292 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.2.post2+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T07:42:00.149028+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.2.post2+tuxcare of django, and is fixed in 4.2.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45115"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45116"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2021-45452"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-22818"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-23833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28346"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-28347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-34265"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-36359"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-23969"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-24580"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-31047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-36053"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-43665"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2023-46695"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T12:33:00.867807+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post21+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post21+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 4.0.post15+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 4.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 4.0.post15+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post20+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post20+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 4.0.post15+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:57:00.104085+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post22+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post22+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@4.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@4.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post18+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 4.0.post15+tuxcare of django, and is fixed in 4.0.post18+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      },
      "action_statement": "Vulnerability CVE-2023-40267 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      },
      "action_statement": "Vulnerability CVE-2023-40590 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post3+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      },
      "action_statement": "Vulnerability CVE-2024-22190 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post3+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post3+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      },
      "action_statement": "Vulnerability CVE-2026-67322 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      },
      "action_statement": "Vulnerability CVE-2026-67323 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      },
      "action_statement": "Vulnerability CVE-2026-67325 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      },
      "action_statement": "Vulnerability CVE-2026-76217 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      },
      "action_statement": "Vulnerability CVE-2026-76218 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      },
      "action_statement": "Vulnerability CVE-2026-76219 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      },
      "action_statement": "Vulnerability CVE-2026-76220 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      },
      "action_statement": "Vulnerability CVE-2026-76222 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      },
      "action_statement": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      },
      "action_statement": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      },
      "action_statement": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      },
      "action_statement": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      },
      "action_statement": "Vulnerability GHSA-539m-9xh6-q6rr affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      },
      "action_statement": "Vulnerability GHSA-6p8h-3wgx-97gf affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      },
      "action_statement": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      },
      "action_statement": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      },
      "action_statement": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      },
      "action_statement": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      },
      "action_statement": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      },
      "action_statement": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      },
      "action_statement": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post3+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      },
      "action_statement": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      },
      "action_statement": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      },
      "action_statement": "Vulnerability GHSA-wvpp-8hx9-p66j affects version 3.1.31.post3+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1839 is fixed in version 4.57.6.post4+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-1839"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4372 is fixed in version 4.57.6.post4+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-4372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-5241 is fixed in version 4.57.6.post4+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-5241"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:07:00.151595+00:00",
      "status_notes": "Vulnerability CVE-2026-80047 affects version 4.57.6.post4+tuxcare of transformers, and is fixed in 4.57.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-80047"
      },
      "action_statement": "Vulnerability CVE-2026-80047 affects version 4.57.6.post4+tuxcare of transformers, and is fixed in 4.57.6.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9856 is fixed in version 4.57.6.post4+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-9856"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.1.10.post5+tuxcare of django. not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.10.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      },
      "action_statement": "Vulnerability CVE-2023-40590 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      },
      "action_statement": "Vulnerability CVE-2024-22190 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      },
      "action_statement": "Vulnerability CVE-2026-67322 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      },
      "action_statement": "Vulnerability CVE-2026-67323 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      },
      "action_statement": "Vulnerability CVE-2026-67325 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      },
      "action_statement": "Vulnerability CVE-2026-76217 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      },
      "action_statement": "Vulnerability CVE-2026-76218 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      },
      "action_statement": "Vulnerability CVE-2026-76219 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      },
      "action_statement": "Vulnerability CVE-2026-76222 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      },
      "action_statement": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      },
      "action_statement": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      },
      "action_statement": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      },
      "action_statement": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      },
      "action_statement": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      },
      "action_statement": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      },
      "action_statement": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      },
      "action_statement": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      },
      "action_statement": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      },
      "action_statement": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      },
      "action_statement": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post7+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post7+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      },
      "action_statement": "Vulnerability CVE-2023-40267 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      },
      "action_statement": "Vulnerability CVE-2023-40590 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post2+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      },
      "action_statement": "Vulnerability CVE-2024-22190 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      },
      "action_statement": "Vulnerability CVE-2026-42215 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post2+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      },
      "action_statement": "Vulnerability CVE-2026-67322 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      },
      "action_statement": "Vulnerability CVE-2026-67323 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      },
      "action_statement": "Vulnerability CVE-2026-67325 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      },
      "action_statement": "Vulnerability CVE-2026-76217 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      },
      "action_statement": "Vulnerability CVE-2026-76218 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      },
      "action_statement": "Vulnerability CVE-2026-76219 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      },
      "action_statement": "Vulnerability CVE-2026-76220 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      },
      "action_statement": "Vulnerability CVE-2026-76222 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      },
      "action_statement": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      },
      "action_statement": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      },
      "action_statement": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      },
      "action_statement": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      },
      "action_statement": "Vulnerability GHSA-539m-9xh6-q6rr affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      },
      "action_statement": "Vulnerability GHSA-6p8h-3wgx-97gf affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      },
      "action_statement": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      },
      "action_statement": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      },
      "action_statement": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      },
      "action_statement": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      },
      "action_statement": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      },
      "action_statement": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      },
      "action_statement": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      },
      "action_statement": "Vulnerability GHSA-mv93-w799-cj2w affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      },
      "action_statement": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      },
      "action_statement": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      },
      "action_statement": "Vulnerability GHSA-wvpp-8hx9-p66j affects version 3.1.31.post2+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post10+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post10+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post10+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post10+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.1.post10+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.1.post10+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post10+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post10+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post10+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post10+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      },
      "action_statement": "Vulnerability CVE-2024-37891 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 2.0.7.post1+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      },
      "action_statement": "Vulnerability CVE-2025-66418 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      },
      "action_statement": "Vulnerability CVE-2025-66471 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:55:00.904119+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:55:00.904119+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 2.0.7.post1+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post6+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post6+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.1.post6+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post9+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post9+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post9+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.1.post9+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.1.post9+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post9+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.1.post9+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.1.post9+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post9+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.1.post9+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.1.post9+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post9+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post9+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post9+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post9+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.2.post9+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.2.post9+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post9+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post9+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post9+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post9+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.2.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      },
      "action_statement": "Vulnerability CVE-2024-38875 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      },
      "action_statement": "Vulnerability CVE-2024-39330 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      },
      "action_statement": "Vulnerability CVE-2024-39614 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post2+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post2+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.1.post2+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      },
      "action_statement": "Vulnerability CVE-2024-39614 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post4+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post4+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.1.post4+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 3.2.25.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 3.2.25.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 3.2.25.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 3.2.25.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 3.2.25.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 3.2.25.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 3.2.25.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 3.2.25.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 3.2.25.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 3.2.25.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 3.2.25.post7+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 3.2.25.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 3.2.25.post7+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 3.2.25.post7+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 3.2.25.post7+tuxcare of django. not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 3.2.25.post7+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 3.2.25.post7+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 3.2.25.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      },
      "action_statement": "Vulnerability CVE-2024-38875 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      },
      "action_statement": "Vulnerability CVE-2024-39330 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      },
      "action_statement": "Vulnerability CVE-2024-39614 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post1+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post1+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.1.post1+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1839 is fixed in version 4.57.6.post2+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-1839"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4372 is fixed in version 4.57.6.post2+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-4372"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-5241 affects version 4.57.6.post2+tuxcare of transformers, and is fixed in 4.57.6.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-5241"
      },
      "action_statement": "Vulnerability CVE-2026-5241 affects version 4.57.6.post2+tuxcare of transformers, and is fixed in 4.57.6.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:07:00.151595+00:00",
      "status_notes": "Vulnerability CVE-2026-80047 affects version 4.57.6.post2+tuxcare of transformers, and is fixed in 4.57.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-80047"
      },
      "action_statement": "Vulnerability CVE-2026-80047 affects version 4.57.6.post2+tuxcare of transformers, and is fixed in 4.57.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9856 affects version 4.57.6.post2+tuxcare of transformers, and is fixed in 4.57.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-9856"
      },
      "action_statement": "Vulnerability CVE-2026-9856 affects version 4.57.6.post2+tuxcare of transformers, and is fixed in 4.57.6.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post12+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post12+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post12+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post12+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post12+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post12+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post12+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post12+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post12+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post12+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post12+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post7+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.2.post7+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.2.post7+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.2.post7+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.2.post7+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.2.post7+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.2.post7+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.2.post7+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.2.post7+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.2.post7+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.2.post7+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post7+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post7+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.2.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:07:00.151595+00:00",
      "status_notes": "Vulnerability CVE-2026-1839 is fixed in version 4.57.6.post5+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-1839"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:07:00.151595+00:00",
      "status_notes": "Vulnerability CVE-2026-4372 is fixed in version 4.57.6.post5+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-4372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:07:00.151595+00:00",
      "status_notes": "Vulnerability CVE-2026-5241 is fixed in version 4.57.6.post5+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-5241"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:07:00.151595+00:00",
      "status_notes": "Vulnerability CVE-2026-80047 is fixed in version 4.57.6.post5+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-80047"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:07:00.151595+00:00",
      "status_notes": "Vulnerability CVE-2026-9856 is fixed in version 4.57.6.post5+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-9856"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post4+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      },
      "action_statement": "Vulnerability CVE-2023-40590 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post4+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      },
      "action_statement": "Vulnerability CVE-2024-22190 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post4+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post4+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      },
      "action_statement": "Vulnerability CVE-2026-67322 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      },
      "action_statement": "Vulnerability CVE-2026-67323 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      },
      "action_statement": "Vulnerability CVE-2026-67325 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      },
      "action_statement": "Vulnerability CVE-2026-76217 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      },
      "action_statement": "Vulnerability CVE-2026-76218 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      },
      "action_statement": "Vulnerability CVE-2026-76219 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post4+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      },
      "action_statement": "Vulnerability CVE-2026-76222 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      },
      "action_statement": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      },
      "action_statement": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      },
      "action_statement": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      },
      "action_statement": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      },
      "action_statement": "Vulnerability GHSA-539m-9xh6-q6rr affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post4+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      },
      "action_statement": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      },
      "action_statement": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      },
      "action_statement": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      },
      "action_statement": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      },
      "action_statement": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      },
      "action_statement": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      },
      "action_statement": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post4+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      },
      "action_statement": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      },
      "action_statement": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post4+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post4+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 is fixed in version 2.0.7.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 2.0.7.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 affects version 2.0.7.post2+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      },
      "action_statement": "Vulnerability CVE-2025-66418 affects version 2.0.7.post2+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 affects version 2.0.7.post2+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      },
      "action_statement": "Vulnerability CVE-2025-66471 affects version 2.0.7.post2+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 2.0.7.post2+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 2.0.7.post2+tuxcare of urllib3, and is fixed in 2.0.7.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 is fixed in version 2.0.7.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:55:00.904119+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 2.0.7.post2+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 2.0.7.post2+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:55:00.904119+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 2.0.7.post2+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 2.0.7.post2+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      },
      "action_statement": "Vulnerability CVE-2024-38875 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      },
      "action_statement": "Vulnerability CVE-2024-39330 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      },
      "action_statement": "Vulnerability CVE-2024-39614 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post3+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post3+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.2.post3+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post8+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post8+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.1.post8+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post8+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post8+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post6+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.2.post6+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post6+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post6+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.2.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1839 is fixed in version 4.57.6.post1+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-1839"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4372 affects version 4.57.6.post1+tuxcare of transformers, and is fixed in 4.57.6.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-4372"
      },
      "action_statement": "Vulnerability CVE-2026-4372 affects version 4.57.6.post1+tuxcare of transformers, and is fixed in 4.57.6.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-5241 affects version 4.57.6.post1+tuxcare of transformers, and is fixed in 4.57.6.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-5241"
      },
      "action_statement": "Vulnerability CVE-2026-5241 affects version 4.57.6.post1+tuxcare of transformers, and is fixed in 4.57.6.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:07:00.151595+00:00",
      "status_notes": "Vulnerability CVE-2026-80047 affects version 4.57.6.post1+tuxcare of transformers, and is fixed in 4.57.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-80047"
      },
      "action_statement": "Vulnerability CVE-2026-80047 affects version 4.57.6.post1+tuxcare of transformers, and is fixed in 4.57.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9856 affects version 4.57.6.post1+tuxcare of transformers, and is fixed in 4.57.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-9856"
      },
      "action_statement": "Vulnerability CVE-2026-9856 affects version 4.57.6.post1+tuxcare of transformers, and is fixed in 4.57.6.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post7+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.1.post7+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post7+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post5+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post5+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.2.post5+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.10.post2+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.1.10.post2+tuxcare of django. not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.10.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post11+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post11+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post11+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post11+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post11+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post11+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post11+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post11+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.10.post4+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.10.post4+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.10.post4+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.10.post4+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.1.10.post4+tuxcare of django. not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.10.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 3.2.25.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 3.2.25.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 3.2.25.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 3.2.25.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 3.2.25.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 3.2.25.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 3.2.25.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 3.2.25.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 3.2.25.post2+tuxcare of django. not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 3.2.25.post2+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      },
      "action_statement": "Vulnerability CVE-2024-39614 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post5+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post5+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.1.post5+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post11+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post11+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      },
      "action_statement": "Vulnerability CVE-2024-39614 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post4+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post4+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.2.post4+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post10+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post10+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post10+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post10+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post10+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      },
      "action_statement": "Vulnerability CVE-2023-40590 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      },
      "action_statement": "Vulnerability CVE-2024-22190 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      },
      "action_statement": "Vulnerability CVE-2026-67322 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      },
      "action_statement": "Vulnerability CVE-2026-67323 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      },
      "action_statement": "Vulnerability CVE-2026-67325 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      },
      "action_statement": "Vulnerability CVE-2026-76217 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      },
      "action_statement": "Vulnerability CVE-2026-76218 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      },
      "action_statement": "Vulnerability CVE-2026-76219 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      },
      "action_statement": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      },
      "action_statement": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      },
      "action_statement": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      },
      "action_statement": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      },
      "action_statement": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      },
      "action_statement": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      },
      "action_statement": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      },
      "action_statement": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      },
      "action_statement": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      },
      "action_statement": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post8+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post8+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      },
      "action_statement": "Vulnerability CVE-2024-38875 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      },
      "action_statement": "Vulnerability CVE-2024-39330 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      },
      "action_statement": "Vulnerability CVE-2024-39614 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post1+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post1+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.2.post1+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      },
      "action_statement": "Vulnerability CVE-2023-40267 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      },
      "action_statement": "Vulnerability CVE-2023-40590 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post1+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      },
      "action_statement": "Vulnerability CVE-2024-22190 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      },
      "action_statement": "Vulnerability CVE-2026-42215 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      },
      "action_statement": "Vulnerability CVE-2026-44244 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      },
      "action_statement": "Vulnerability CVE-2026-67322 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      },
      "action_statement": "Vulnerability CVE-2026-67323 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      },
      "action_statement": "Vulnerability CVE-2026-67325 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      },
      "action_statement": "Vulnerability CVE-2026-76217 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      },
      "action_statement": "Vulnerability CVE-2026-76218 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      },
      "action_statement": "Vulnerability CVE-2026-76219 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      },
      "action_statement": "Vulnerability CVE-2026-76220 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      },
      "action_statement": "Vulnerability CVE-2026-76222 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      },
      "action_statement": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      },
      "action_statement": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      },
      "action_statement": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      },
      "action_statement": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      },
      "action_statement": "Vulnerability GHSA-539m-9xh6-q6rr affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      },
      "action_statement": "Vulnerability GHSA-6p8h-3wgx-97gf affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      },
      "action_statement": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      },
      "action_statement": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      },
      "action_statement": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      },
      "action_statement": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      },
      "action_statement": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      },
      "action_statement": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      },
      "action_statement": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      },
      "action_statement": "Vulnerability GHSA-mv93-w799-cj2w affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      },
      "action_statement": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      },
      "action_statement": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      },
      "action_statement": "Vulnerability GHSA-wvpp-8hx9-p66j affects version 3.1.31.post1+tuxcare of gitpython, and is fixed in 3.1.31.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post6+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      },
      "action_statement": "Vulnerability CVE-2023-40590 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post6+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      },
      "action_statement": "Vulnerability CVE-2024-22190 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post6+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post6+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      },
      "action_statement": "Vulnerability CVE-2026-67322 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      },
      "action_statement": "Vulnerability CVE-2026-67323 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      },
      "action_statement": "Vulnerability CVE-2026-67325 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      },
      "action_statement": "Vulnerability CVE-2026-76217 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      },
      "action_statement": "Vulnerability CVE-2026-76218 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      },
      "action_statement": "Vulnerability CVE-2026-76219 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post6+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      },
      "action_statement": "Vulnerability CVE-2026-76222 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      },
      "action_statement": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      },
      "action_statement": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      },
      "action_statement": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      },
      "action_statement": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr is fixed in version 3.1.31.post6+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post6+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      },
      "action_statement": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      },
      "action_statement": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      },
      "action_statement": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      },
      "action_statement": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      },
      "action_statement": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      },
      "action_statement": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      },
      "action_statement": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post6+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 is fixed in version 3.1.31.post6+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      },
      "action_statement": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post6+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post6+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      },
      "action_statement": "Vulnerability CVE-2024-38875 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      },
      "action_statement": "Vulnerability CVE-2024-39330 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      },
      "action_statement": "Vulnerability CVE-2024-39614 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post2+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post2+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.2.post2+tuxcare of django, and is fixed in 5.0.2.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post13+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post13+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post13+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post13+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post13+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post13+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post13+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 is fixed in version 2.0.7.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 2.0.7.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 2.0.7.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 is fixed in version 2.0.7.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 is fixed in version 2.0.7.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 is fixed in version 2.0.7.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:55:00.904119+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 2.0.7.post3+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 2.0.7.post3+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:55:00.904119+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 2.0.7.post3+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 2.0.7.post3+tuxcare of urllib3, and is fixed in 2.0.7.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post8+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.2.post8+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.2.post8+tuxcare of django, and is fixed in 5.0.2.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.2.post8+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.2.post8+tuxcare of django, and is fixed in 5.0.2.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post8+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post8+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post8+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.2.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.10.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.1.10.post1+tuxcare of django. not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.1.10.post1+tuxcare of django, and is fixed in 5.1.10.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 3.2.25.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 3.2.25.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 3.2.25.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 3.2.25.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 3.2.25.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 3.2.25.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 3.2.25.post1+tuxcare of django. not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 3.2.25.post1+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      },
      "action_statement": "Vulnerability CVE-2026-67322 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      },
      "action_statement": "Vulnerability CVE-2026-67323 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      },
      "action_statement": "Vulnerability CVE-2026-67325 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      },
      "action_statement": "Vulnerability CVE-2026-76217 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      },
      "action_statement": "Vulnerability CVE-2026-76218 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      },
      "action_statement": "Vulnerability CVE-2026-76219 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      },
      "action_statement": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      },
      "action_statement": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      },
      "action_statement": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      },
      "action_statement": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      },
      "action_statement": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      },
      "action_statement": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      },
      "action_statement": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      },
      "action_statement": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      },
      "action_statement": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      },
      "action_statement": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post9+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post9+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      },
      "action_statement": "Vulnerability CVE-2026-76217 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      },
      "action_statement": "Vulnerability CVE-2026-76219 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      },
      "action_statement": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      },
      "action_statement": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      },
      "action_statement": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      },
      "action_statement": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post10+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post10+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 3.2.25.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 3.2.25.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 3.2.25.post8+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 3.2.25.post8+tuxcare of django. not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 3.2.25.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 3.2.25.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 3.2.25.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 3.2.25.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 3.2.25.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 3.2.25.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 3.2.25.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 3.2.25.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 3.2.25.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 3.2.25.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 3.2.25.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 3.2.25.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 3.2.25.post5+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 3.2.25.post5+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 3.2.25.post5+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 3.2.25.post5+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 3.2.25.post5+tuxcare of django. not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 3.2.25.post5+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 3.2.25.post5+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 3.2.25.post5+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 3.2.25.post5+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1839 is fixed in version 4.57.6.post3+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-1839"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4372 is fixed in version 4.57.6.post3+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-4372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-5241 is fixed in version 4.57.6.post3+tuxcare of transformers.",
      "vulnerability": {
        "name": "CVE-2026-5241"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:07:00.151595+00:00",
      "status_notes": "Vulnerability CVE-2026-80047 affects version 4.57.6.post3+tuxcare of transformers, and is fixed in 4.57.6.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-80047"
      },
      "action_statement": "Vulnerability CVE-2026-80047 affects version 4.57.6.post3+tuxcare of transformers, and is fixed in 4.57.6.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/transformers@4.57.6.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/transformers@4.57.6.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9856 affects version 4.57.6.post3+tuxcare of transformers, and is fixed in 4.57.6.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-9856"
      },
      "action_statement": "Vulnerability CVE-2026-9856 affects version 4.57.6.post3+tuxcare of transformers, and is fixed in 4.57.6.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post14+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.10.post3+tuxcare of django, and is fixed in 5.1.10.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.10.post3+tuxcare of django, and is fixed in 5.1.10.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.10.post3+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.10.post3+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.10.post3+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.10.post3+tuxcare of django, and is fixed in 5.1.10.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.1.10.post3+tuxcare of django. not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.1.10 is not affected by CVE-2026-53878. While DomainNameValidator does accept domain names with trailing newlines (due to Python regex '$' matching before newlines), Django itself is protected by HttpResponse's runtime newline checks. All HTTP responses in Django go through ResponseHeaders._convert_to_charset() which explicitly checks for and rejects '\\n' and '\\r' characters in header ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.10.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.10.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.10.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 3.2.25.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 3.2.25.post4+tuxcare of django, and is fixed in 3.2.25.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 3.2.25.post4+tuxcare of django, and is fixed in 3.2.25.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 3.2.25.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 3.2.25.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 3.2.25.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 3.2.25.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 3.2.25.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 3.2.25.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 3.2.25.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 3.2.25.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 3.2.25.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 3.2.25.post4+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 3.2.25.post4+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 3.2.25.post4+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 3.2.25.post4+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 3.2.25.post4+tuxcare of django. not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 3.2.25.post4+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 3.2.25.post4+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 3.2.25.post4+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 3.2.25.post4+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      },
      "action_statement": "Vulnerability CVE-2024-38875 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      },
      "action_statement": "Vulnerability CVE-2024-39330 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      },
      "action_statement": "Vulnerability CVE-2024-39614 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post3+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.1.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.1.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.1.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.1.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.1.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.1.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.1.post3+tuxcare of django. not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.1 is not affected by CVE-2026-53878. The CVE describes a vulnerability in the DomainNameValidator class introduced in Django 5.1, where regex patterns without proper anchors allowed domains containing newlines to pass validation. Django 5.0.1 does not have this class. All domain validation mechanisms in 5.0.1 (_simple_domain_name_validator, EmailValidator.domain_regex, URLValidator.u..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.1.post3+tuxcare of django, and is fixed in 5.0.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:54:00.136665+00:00",
      "status_notes": "Vulnerability CVE-2024-37891 is fixed in version 2.0.7.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2024-37891"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:54:00.136665+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 2.0.7.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:54:00.136665+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 2.0.7.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:54:00.136665+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 is fixed in version 2.0.7.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:54:00.136665+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 is fixed in version 2.0.7.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:54:00.136665+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 is fixed in version 2.0.7.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:55:00.904119+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 is fixed in version 2.0.7.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@2.0.7.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@2.0.7.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:55:00.904119+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 is fixed in version 2.0.7.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 3.2.25.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 3.2.25.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 3.2.25.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 3.2.25.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 3.2.25.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 3.2.25.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 3.2.25.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 3.2.25.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 3.2.25.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 3.2.25.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 3.2.25.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 3.2.25.post6+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 3.2.25.post6+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 3.2.25.post6+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 3.2.25.post6+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 3.2.25.post6+tuxcare of django. not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 3.2.25.post6+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 3.2.25.post6+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 3.2.25.post6+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 3.2.25.post6+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40267 is fixed in version 3.1.31.post5+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-40267"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40590 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-40590"
      },
      "action_statement": "Vulnerability CVE-2023-40590 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post5+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2023-41040"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22190 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-22190"
      },
      "action_statement": "Vulnerability CVE-2024-22190 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post5+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-42215"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42284 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42284"
      },
      "action_statement": "Vulnerability CVE-2026-42284 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44243 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44243"
      },
      "action_statement": "Vulnerability CVE-2026-44243 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post5+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-44244"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67322 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67322"
      },
      "action_statement": "Vulnerability CVE-2026-67322 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67323 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67323"
      },
      "action_statement": "Vulnerability CVE-2026-67323 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67325 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67325"
      },
      "action_statement": "Vulnerability CVE-2026-67325 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76217 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76217"
      },
      "action_statement": "Vulnerability CVE-2026-76217 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76218 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76218"
      },
      "action_statement": "Vulnerability CVE-2026-76218 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76219 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76219"
      },
      "action_statement": "Vulnerability CVE-2026-76219 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76220 is fixed in version 3.1.31.post5+tuxcare of gitpython.",
      "vulnerability": {
        "name": "CVE-2026-76220"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-76222 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-76222"
      },
      "action_statement": "Vulnerability CVE-2026-76222 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78675 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78675"
      },
      "action_statement": "Vulnerability CVE-2026-78675 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78676 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78676"
      },
      "action_statement": "Vulnerability CVE-2026-78676 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78677 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78677"
      },
      "action_statement": "Vulnerability CVE-2026-78677 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78678 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78678"
      },
      "action_statement": "Vulnerability CVE-2026-78678 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-78679 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-78679"
      },
      "action_statement": "Vulnerability CVE-2026-78679 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87817 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87817"
      },
      "action_statement": "Vulnerability CVE-2026-87817 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability CVE-2026-87819 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-87819"
      },
      "action_statement": "Vulnerability CVE-2026-87819 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-2f96-g7mh-g2hx"
      },
      "action_statement": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3f7w-8rr8-f37f"
      },
      "action_statement": "Vulnerability GHSA-3f7w-8rr8-f37f affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3rp5-jjmw-4wv2"
      },
      "action_statement": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4gmw-gg2m-w46p"
      },
      "action_statement": "Vulnerability GHSA-4gmw-gg2m-w46p affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-539m-9xh6-q6rr is fixed in version 3.1.31.post5+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-539m-9xh6-q6rr"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:46:00.077951+00:00",
      "status_notes": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare.",
      "vulnerability": {
        "name": "GHSA-59cr-6r3x-644w"
      },
      "action_statement": "Vulnerability GHSA-59cr-6r3x-644w affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6p8h-3wgx-97gf is fixed in version 3.1.31.post5+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-6p8h-3wgx-97gf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94p4-4cq8-9g67"
      },
      "action_statement": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-956x-8gvw-wg5v"
      },
      "action_statement": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9rj7-rf2p-w77r"
      },
      "action_statement": "Vulnerability GHSA-9rj7-rf2p-w77r affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-fjr4-x663-mwxc"
      },
      "action_statement": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hh9p-6wh2-4mfc"
      },
      "action_statement": "Vulnerability GHSA-hh9p-6wh2-4mfc affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-hmq2-w58f-27jc"
      },
      "action_statement": "Vulnerability GHSA-hmq2-w58f-27jc affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm78-9fvv-mhgr"
      },
      "action_statement": "Vulnerability GHSA-jm78-9fvv-mhgr affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post5+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-mv93-w799-cj2w"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-p538-c434-8v24"
      },
      "action_statement": "Vulnerability GHSA-p538-c434-8v24 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-rwj8-pgh3-r573"
      },
      "action_statement": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post5+tuxcare of gitpython, and is fixed in 3.1.31.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/gitpython@3.1.31.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/gitpython@3.1.31.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wvpp-8hx9-p66j is fixed in version 3.1.31.post5+tuxcare of gitpython.",
      "vulnerability": {
        "name": "GHSA-wvpp-8hx9-p66j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 3.2.25.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 3.2.25.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 3.2.25.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T23:34:00.080502+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 3.2.25.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 3.2.25.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T20:24:00.091047+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 3.2.25.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 3.2.25.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 3.2.25.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 3.2.25.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 3.2.25.post3+tuxcare of django. not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici...",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 3.2.25 is not affected by CVE-2026-53878. The CVE concerns `DomainNameValidator` (introduced in Django 5.x/6.x) which does not prohibit newlines in domain names. Django 3.2.25 lacks this class entirely. The existing domain validators (`_simple_domain_name_validator` in sites/models.py, `EmailValidator.validate_domain_part()` in core/validators.py) already prohibit newlines either explici..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:23:00.306633+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@3.2.25.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@3.2.25.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 3.2.25.post3+tuxcare of django, and is fixed in 3.2.25.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post6+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post6+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.post6+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.4.post4+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.4.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.26.20.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.26.20.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 is fixed in version 1.26.20.post2+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.26.20.post2+tuxcare of urllib3, and is fixed in 1.26.20.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.26.20.post2+tuxcare of urllib3, and is fixed in 1.26.20.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.26.20.post2+tuxcare of urllib3, and is fixed in 1.26.20.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.26.20.post2+tuxcare of urllib3, and is fixed in 1.26.20.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 1.26.20.post2+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 1.26.20.post2+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.26.20.post2+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.26.20.post2+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-45768 is fixed in version 2.10.1.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2025-45768"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.10.1.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.10.1.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102271 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102271"
      },
      "action_statement": "Vulnerability CVE-2026-102271 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2026-102274 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102274"
      },
      "action_statement": "Vulnerability CVE-2026-102274 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      },
      "action_statement": "Vulnerability CVE-2026-32597 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 2.10.1.post1+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48523 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48523"
      },
      "action_statement": "Vulnerability CVE-2026-48523 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "action_statement": "Vulnerability CVE-2026-48524 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "action_statement": "Vulnerability CVE-2026-48525 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      },
      "action_statement": "Vulnerability CVE-2026-48526 affects version 2.10.1.post1+tuxcare of pyjwt, and is fixed in 2.10.1.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:25:31.426299+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 affects version 6.1.0.post6+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      },
      "action_statement": "Vulnerability CVE-2026-82397 affects version 6.1.0.post6+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post6+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post6+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post6+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      },
      "action_statement": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post6+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post6+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post6+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post6+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post6+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post10+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post10+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post10+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.post10+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post10+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.post10+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.post10+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.post10+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.post10+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      },
      "action_statement": "Vulnerability CVE-2023-28370 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 5.1.1.post1+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      },
      "action_statement": "Vulnerability CVE-2025-47287 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      },
      "action_statement": "Vulnerability CVE-2025-67724 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      },
      "action_statement": "Vulnerability CVE-2025-67725 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      },
      "action_statement": "Vulnerability CVE-2025-67726 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      },
      "action_statement": "Vulnerability CVE-2026-31958 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      },
      "action_statement": "Vulnerability CVE-2026-35536 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      },
      "action_statement": "Vulnerability CVE-2026-49853 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      },
      "action_statement": "Vulnerability CVE-2026-49854 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      },
      "action_statement": "Vulnerability CVE-2026-49855 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      },
      "action_statement": "Vulnerability CVE-2026-82397 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      },
      "action_statement": "Vulnerability GHSA-753j-mpmx-qq6g affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      },
      "action_statement": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      },
      "action_statement": "Vulnerability GHSA-8423-8fgw-73vq affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      },
      "action_statement": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      },
      "action_statement": "Vulnerability GHSA-qppv-j76h-2rpx affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      },
      "action_statement": "Vulnerability GHSA-w235-7p84-xx57 affects version 5.1.1.post1+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 5.1.1.post4+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 5.1.1.post4+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 5.1.1.post4+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 5.1.1.post4+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post4+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post4+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 5.1.1.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post16+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post16+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post16+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post16+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.post16+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      },
      "action_statement": "Vulnerability CVE-2023-28370 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      },
      "action_statement": "Vulnerability CVE-2025-67724 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      },
      "action_statement": "Vulnerability CVE-2025-67725 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:25:31.426299+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      },
      "action_statement": "Vulnerability CVE-2025-67726 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      },
      "action_statement": "Vulnerability CVE-2026-49853 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      },
      "action_statement": "Vulnerability CVE-2026-49854 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      },
      "action_statement": "Vulnerability CVE-2026-82397 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      },
      "action_statement": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      },
      "action_statement": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 6.1.0.post3+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.9.post6+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.9.post6+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.9.post6+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.9.post6+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.9.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "action_statement": "Vulnerability CVE-2026-53878 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.1.post4+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-45768 is fixed in version 2.8.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2025-45768"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.8.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.8.0.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102271 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102271"
      },
      "action_statement": "Vulnerability CVE-2026-102271 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      },
      "action_statement": "Vulnerability CVE-2026-32597 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 2.8.0.post2+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522: PyJWKClient URI scheme SSRF vulnerability is already fixed in the target repository. The fix was introduced via commit 67029b7 (Backport CVE-2026-48526 to 2.8.0) on 2026-07-13, which added URI scheme validation to reject non-HTTP(S) schemes (file://, ftp://, data:, etc.) before any fetch operation. While the version number was later reverted from 2.8.0.post2+tuxcare to 2.8.0.pos...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-48522: PyJWKClient URI scheme SSRF vulnerability is already fixed in the target repository. The fix was introduced via commit 67029b7 (Backport CVE-2026-48526 to 2.8.0) on 2026-07-13, which added URI scheme validation to reject non-HTTP(S) schemes (file://, ftp://, data:, etc.) before any fetch operation. While the version number was later reverted from 2.8.0.post2+tuxcare to 2.8.0.pos..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "action_statement": "Vulnerability CVE-2026-48524 affects version 2.8.0.post2+tuxcare of pyjwt, and is fixed in 2.8.0.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 does not affect version 2.8.0.post2+tuxcare of pyjwt. pyjwt 2.8.0 is not affected by CVE-2026-48525. The upstream fix (jpadilla/pyjwt@95791b1) forwards the opt-in 'enforce_minimum_key_length' option into sig_options in api_jwt.py; the vulnerability is that setting that option per call had no effect, letting an undersized RSA key through. Branch tuxcare-current/2.8.0 contains none of that machinery (no enforce_minimum_key_length, no sig_options, no InsecureKeyLengthWarning in jwt/). The CVE-2025-45768 backport (796cc35, PYELSCVE-180) instead enforces a minimum 2048-bit RSA key unconditionally in RSAAlgorithm.prepare_key, which no option can disable. Verified on the released 2.8.0.post3+tuxcare wheel from Nexus with a fresh 1024-bit RSA key: rejected with no options, with enforce_minimum_key_length=False and with verify_signature=False; a 2048-bit key still round-trips. MR !18 was changelog-only and has been closed. Jira PYELSCVE-1216.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "impact_statement": "pyjwt 2.8.0 is not affected by CVE-2026-48525. The upstream fix (jpadilla/pyjwt@95791b1) forwards the opt-in 'enforce_minimum_key_length' option into sig_options in api_jwt.py; the vulnerability is that setting that option per call had no effect, letting an undersized RSA key through. Branch tuxcare-current/2.8.0 contains none of that machinery (no enforce_minimum_key_length, no sig_options, no InsecureKeyLengthWarning in jwt/). The CVE-2025-45768 backport (796cc35, PYELSCVE-180) instead enforces a minimum 2048-bit RSA key unconditionally in RSAAlgorithm.prepare_key, which no option can disable. Verified on the released 2.8.0.post3+tuxcare wheel from Nexus with a fresh 1024-bit RSA key: rejected with no options, with enforce_minimum_key_length=False and with verify_signature=False; a 2048-bit key still round-trips. MR !18 was changelog-only and has been closed. Jira PYELSCVE-1216."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 2.8.0.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post7+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post7+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.post7+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-45768 is fixed in version 2.10.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2025-45768"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.10.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.10.1.post2+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102271 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102271"
      },
      "action_statement": "Vulnerability CVE-2026-102271 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2026-102274 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102274"
      },
      "action_statement": "Vulnerability CVE-2026-102274 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      },
      "action_statement": "Vulnerability CVE-2026-32597 affects version 2.10.1.post2+tuxcare of pyjwt, and is fixed in 2.10.1.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 2.10.1.post2+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48523 is fixed in version 2.10.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48523"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 is fixed in version 2.10.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48524"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 is fixed in version 2.10.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 2.10.1.post2+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post9+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post9+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:09:00.313196+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post9+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post9+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post9+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post9+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post9+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.post9+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.4.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      },
      "action_statement": "Vulnerability CVE-2025-32873 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "action_statement": "Vulnerability CVE-2026-53878 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.1.4.post1+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.9.post5+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.9.post5+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.9.post5+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.9.post5+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.9.post5+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.9.post5+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.9.post5+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.9.post5+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.9.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.post6+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      },
      "action_statement": "Vulnerability CVE-2025-32873 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.4.post3+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.4.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post12+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post12+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post12+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post12+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post12+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.post12+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      },
      "action_statement": "Vulnerability CVE-2024-38875 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      },
      "action_statement": "Vulnerability CVE-2024-39330 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "action_statement": "Vulnerability CVE-2024-41990 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post2+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post2+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.post2+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post13+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post13+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post13+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post13+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post13+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.post13+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      },
      "action_statement": "Vulnerability CVE-2023-28370 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post1+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post1+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      },
      "action_statement": "Vulnerability CVE-2025-67724 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      },
      "action_statement": "Vulnerability CVE-2025-67725 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:25:31.426299+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      },
      "action_statement": "Vulnerability CVE-2025-67726 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      },
      "action_statement": "Vulnerability CVE-2026-31958 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      },
      "action_statement": "Vulnerability CVE-2026-35536 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      },
      "action_statement": "Vulnerability CVE-2026-49853 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      },
      "action_statement": "Vulnerability CVE-2026-49854 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      },
      "action_statement": "Vulnerability CVE-2026-49855 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      },
      "action_statement": "Vulnerability CVE-2026-82397 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      },
      "action_statement": "Vulnerability GHSA-753j-mpmx-qq6g affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      },
      "action_statement": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      },
      "action_statement": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      },
      "action_statement": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      },
      "action_statement": "Vulnerability GHSA-qppv-j76h-2rpx affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      },
      "action_statement": "Vulnerability GHSA-w235-7p84-xx57 affects version 6.1.0.post1+tuxcare of tornado, and is fixed in 6.1.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      },
      "action_statement": "Vulnerability CVE-2025-32873 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "action_statement": "Vulnerability CVE-2026-53878 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.1.post3+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.26.20.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.26.20.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 is fixed in version 1.26.20.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 is fixed in version 1.26.20.post3+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.26.20.post3+tuxcare of urllib3, and is fixed in 1.26.20.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.26.20.post3+tuxcare of urllib3, and is fixed in 1.26.20.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 1.26.20.post3+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 1.26.20.post3+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.26.20.post3+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.26.20.post3+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.26.20.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.26.20.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 is fixed in version 1.26.20.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 is fixed in version 1.26.20.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 is fixed in version 1.26.20.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 is fixed in version 1.26.20.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 is fixed in version 1.26.20.post5+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.26.20.post1+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      },
      "action_statement": "Vulnerability CVE-2025-66418 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      },
      "action_statement": "Vulnerability CVE-2025-66471 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      },
      "action_statement": "Vulnerability CVE-2026-21441 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      },
      "action_statement": "Vulnerability CVE-2026-44431 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.26.20.post1+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.4.post5+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.4.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      },
      "action_statement": "Vulnerability CVE-2024-38875 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      },
      "action_statement": "Vulnerability CVE-2024-39330 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      },
      "action_statement": "Vulnerability CVE-2024-39614 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "action_statement": "Vulnerability CVE-2024-41990 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post1+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post1+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.post1+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.9.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.9.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "action_statement": "Vulnerability CVE-2026-53878 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.1.9.post2+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:25:31.426299+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 affects version 6.1.0.post7+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      },
      "action_statement": "Vulnerability CVE-2026-82397 affects version 6.1.0.post7+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post7+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post7+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post7+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      },
      "action_statement": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post7+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post7+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post7+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post7+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post7+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post7+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      },
      "action_statement": "Vulnerability CVE-2023-28370 affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:25:31.426299+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      },
      "action_statement": "Vulnerability CVE-2026-82397 affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      },
      "action_statement": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post5+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post11+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post11+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post11+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post11+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post11+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.post11+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.post7+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      },
      "action_statement": "Vulnerability CVE-2025-32873 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "action_statement": "Vulnerability CVE-2026-53878 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.1.post2+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.9.post3+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.9.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post10+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.9.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "action_statement": "Vulnerability CVE-2026-53878 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.1.9.post1+tuxcare of django, and is fixed in 5.1.9.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-45768 is fixed in version 2.10.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2025-45768"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.10.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.10.1.post3+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102271 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102271"
      },
      "action_statement": "Vulnerability CVE-2026-102271 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2026-102274 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102274"
      },
      "action_statement": "Vulnerability CVE-2026-102274 affects version 2.10.1.post3+tuxcare of pyjwt, and is fixed in 2.10.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 is fixed in version 2.10.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 2.10.1.post3+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48523 is fixed in version 2.10.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48523"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 is fixed in version 2.10.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48524"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 is fixed in version 2.10.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 2.10.1.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.9.post4+tuxcare of django, and is fixed in 5.1.9.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.9.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-45768 is fixed in version 2.8.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2025-45768"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.8.0.post1+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.8.0.post1+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102271 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102271"
      },
      "action_statement": "Vulnerability CVE-2026-102271 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      },
      "action_statement": "Vulnerability CVE-2026-32597 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 2.8.0.post1+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522: PyJWKClient URI scheme SSRF vulnerability is already fixed in the target repository. The fix was introduced via commit 67029b7 (Backport CVE-2026-48526 to 2.8.0) on 2026-07-13, which added URI scheme validation to reject non-HTTP(S) schemes (file://, ftp://, data:, etc.) before any fetch operation. While the version number was later reverted from 2.8.0.post2+tuxcare to 2.8.0.pos...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-48522: PyJWKClient URI scheme SSRF vulnerability is already fixed in the target repository. The fix was introduced via commit 67029b7 (Backport CVE-2026-48526 to 2.8.0) on 2026-07-13, which added URI scheme validation to reject non-HTTP(S) schemes (file://, ftp://, data:, etc.) before any fetch operation. While the version number was later reverted from 2.8.0.post2+tuxcare to 2.8.0.pos..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48524"
      },
      "action_statement": "Vulnerability CVE-2026-48524 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 does not affect version 2.8.0.post1+tuxcare of pyjwt. pyjwt 2.8.0 is not affected by CVE-2026-48525. The upstream fix (jpadilla/pyjwt@95791b1) forwards the opt-in 'enforce_minimum_key_length' option into sig_options in api_jwt.py; the vulnerability is that setting that option per call had no effect, letting an undersized RSA key through. Branch tuxcare-current/2.8.0 contains none of that machinery (no enforce_minimum_key_length, no sig_options, no InsecureKeyLengthWarning in jwt/). The CVE-2025-45768 backport (796cc35, PYELSCVE-180) instead enforces a minimum 2048-bit RSA key unconditionally in RSAAlgorithm.prepare_key, which no option can disable. Verified on the released 2.8.0.post3+tuxcare wheel from Nexus with a fresh 1024-bit RSA key: rejected with no options, with enforce_minimum_key_length=False and with verify_signature=False; a 2048-bit key still round-trips. MR !18 was changelog-only and has been closed. Jira PYELSCVE-1216.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "impact_statement": "pyjwt 2.8.0 is not affected by CVE-2026-48525. The upstream fix (jpadilla/pyjwt@95791b1) forwards the opt-in 'enforce_minimum_key_length' option into sig_options in api_jwt.py; the vulnerability is that setting that option per call had no effect, letting an undersized RSA key through. Branch tuxcare-current/2.8.0 contains none of that machinery (no enforce_minimum_key_length, no sig_options, no InsecureKeyLengthWarning in jwt/). The CVE-2025-45768 backport (796cc35, PYELSCVE-180) instead enforces a minimum 2048-bit RSA key unconditionally in RSAAlgorithm.prepare_key, which no option can disable. Verified on the released 2.8.0.post3+tuxcare wheel from Nexus with a fresh 1024-bit RSA key: rejected with no options, with enforce_minimum_key_length=False and with verify_signature=False; a 2048-bit key still round-trips. MR !18 was changelog-only and has been closed. Jira PYELSCVE-1216."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      },
      "action_statement": "Vulnerability CVE-2026-48526 affects version 2.8.0.post1+tuxcare of pyjwt, and is fixed in 2.8.0.post2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/sentence-transformers@2.7.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/sentence-transformers@2.7.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10370 is fixed in version 2.7.0.post2+tuxcare of sentence-transformers.",
      "vulnerability": {
        "name": "AIKIDO-2024-10370"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/sentence-transformers@2.7.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/sentence-transformers@2.7.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T10:48:20.051130+00:00",
      "status_notes": "Vulnerability CVE-2026-68770 affects version 2.7.0.post2+tuxcare of sentence-transformers, and is fixed in 2.7.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-68770"
      },
      "action_statement": "Vulnerability CVE-2026-68770 affects version 2.7.0.post2+tuxcare of sentence-transformers, and is fixed in 2.7.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      },
      "action_statement": "Vulnerability CVE-2023-28370 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post2+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post2+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      },
      "action_statement": "Vulnerability CVE-2025-67724 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      },
      "action_statement": "Vulnerability CVE-2025-67725 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:25:31.426299+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      },
      "action_statement": "Vulnerability CVE-2025-67726 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post2+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post2+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      },
      "action_statement": "Vulnerability CVE-2026-49853 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      },
      "action_statement": "Vulnerability CVE-2026-49854 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      },
      "action_statement": "Vulnerability CVE-2026-49855 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      },
      "action_statement": "Vulnerability CVE-2026-82397 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post2+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post2+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      },
      "action_statement": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      },
      "action_statement": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 6.1.0.post2+tuxcare of tornado, and is fixed in 6.1.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post2+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post2+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.4.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      },
      "action_statement": "Vulnerability CVE-2025-32873 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.4.post2+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "action_statement": "Vulnerability CVE-2026-53878 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.1.4.post2+tuxcare of django, and is fixed in 5.1.4.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post1+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      },
      "action_statement": "Vulnerability CVE-2025-32873 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      },
      "action_statement": "Vulnerability CVE-2025-59681 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "action_statement": "Vulnerability CVE-2026-53878 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.1.post1+tuxcare of django, and is fixed in 5.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.post9+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.post9+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.post9+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.post9+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.post9+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.post9+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.post9+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.post9+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.post9+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.post9+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.post9+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-50181 is fixed in version 1.26.20.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-50181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66418 is fixed in version 1.26.20.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66418"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66471 is fixed in version 1.26.20.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2025-66471"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-21441 is fixed in version 1.26.20.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-21441"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44431 is fixed in version 1.26.20.post4+tuxcare of urllib3.",
      "vulnerability": {
        "name": "CVE-2026-44431"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-97687 affects version 1.26.20.post4+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "action_statement": "Vulnerability CVE-2026-97687 affects version 1.26.20.post4+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/urllib3@1.26.20.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:30:26.237167+00:00",
      "status_notes": "Vulnerability CVE-2026-97689 affects version 1.26.20.post4+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "action_statement": "Vulnerability CVE-2026-97689 affects version 1.26.20.post4+tuxcare of urllib3, and is fixed in 1.26.20.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2025-45768 is fixed in version 2.10.1.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2025-45768"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.10.1.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.10.1.post4+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102271 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102271"
      },
      "action_statement": "Vulnerability CVE-2026-102271 affects version 2.10.1.post4+tuxcare of pyjwt, and is fixed in 2.10.1.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2026-102274 is fixed in version 2.10.1.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102274"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 is fixed in version 2.10.1.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 2.10.1.post4+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2026-48523 is fixed in version 2.10.1.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48523"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 is fixed in version 2.10.1.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48524"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 is fixed in version 2.10.1.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T05:25:00.094068+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 2.10.1.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.9.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.9.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:25:00.256695+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.9.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-45768 is fixed in version 2.8.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2025-45768"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      },
      "action_statement": "Vulnerability CVE-2026-101917 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.8.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.8.0.post3+tuxcare of pyjwt."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      },
      "action_statement": "Vulnerability CVE-2026-102267 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      },
      "action_statement": "Vulnerability CVE-2026-102268 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      },
      "action_statement": "Vulnerability CVE-2026-102269 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      },
      "action_statement": "Vulnerability CVE-2026-102270 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102271 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-102271"
      },
      "action_statement": "Vulnerability CVE-2026-102271 affects version 2.8.0.post3+tuxcare of pyjwt, and is fixed in 2.8.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 is fixed in version 2.8.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 2.8.0.post3+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522: PyJWKClient URI scheme SSRF vulnerability is already fixed in the target repository. The fix was introduced via commit 67029b7 (Backport CVE-2026-48526 to 2.8.0) on 2026-07-13, which added URI scheme validation to reject non-HTTP(S) schemes (file://, ftp://, data:, etc.) before any fetch operation. While the version number was later reverted from 2.8.0.post2+tuxcare to 2.8.0.pos...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-48522: PyJWKClient URI scheme SSRF vulnerability is already fixed in the target repository. The fix was introduced via commit 67029b7 (Backport CVE-2026-48526 to 2.8.0) on 2026-07-13, which added URI scheme validation to reject non-HTTP(S) schemes (file://, ftp://, data:, etc.) before any fetch operation. While the version number was later reverted from 2.8.0.post2+tuxcare to 2.8.0.pos..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 is fixed in version 2.8.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48524"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 does not affect version 2.8.0.post3+tuxcare of pyjwt. pyjwt 2.8.0 is not affected by CVE-2026-48525. The upstream fix (jpadilla/pyjwt@95791b1) forwards the opt-in 'enforce_minimum_key_length' option into sig_options in api_jwt.py; the vulnerability is that setting that option per call had no effect, letting an undersized RSA key through. Branch tuxcare-current/2.8.0 contains none of that machinery (no enforce_minimum_key_length, no sig_options, no InsecureKeyLengthWarning in jwt/). The CVE-2025-45768 backport (796cc35, PYELSCVE-180) instead enforces a minimum 2048-bit RSA key unconditionally in RSAAlgorithm.prepare_key, which no option can disable. Verified on the released 2.8.0.post3+tuxcare wheel from Nexus with a fresh 1024-bit RSA key: rejected with no options, with enforce_minimum_key_length=False and with verify_signature=False; a 2048-bit key still round-trips. MR !18 was changelog-only and has been closed. Jira PYELSCVE-1216.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "impact_statement": "pyjwt 2.8.0 is not affected by CVE-2026-48525. The upstream fix (jpadilla/pyjwt@95791b1) forwards the opt-in 'enforce_minimum_key_length' option into sig_options in api_jwt.py; the vulnerability is that setting that option per call had no effect, letting an undersized RSA key through. Branch tuxcare-current/2.8.0 contains none of that machinery (no enforce_minimum_key_length, no sig_options, no InsecureKeyLengthWarning in jwt/). The CVE-2025-45768 backport (796cc35, PYELSCVE-180) instead enforces a minimum 2048-bit RSA key unconditionally in RSAAlgorithm.prepare_key, which no option can disable. Verified on the released 2.8.0.post3+tuxcare wheel from Nexus with a fresh 1024-bit RSA key: rejected with no options, with enforce_minimum_key_length=False and with verify_signature=False; a 2048-bit key still round-trips. MR !18 was changelog-only and has been closed. Jira PYELSCVE-1216."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 2.8.0.post3+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:25:31.426299+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post8+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post8+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post8+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post8+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post8+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post8+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post8+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post5+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post5+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.post5+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.post8+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-45768 is fixed in version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2025-45768"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 is fixed in version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.8.0.post4+tuxcare of pyjwt."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 is fixed in version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 is fixed in version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 is fixed in version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 is fixed in version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-102271 is fixed in version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 is fixed in version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 2.8.0.post4+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522: PyJWKClient URI scheme SSRF vulnerability is already fixed in the target repository. The fix was introduced via commit 67029b7 (Backport CVE-2026-48526 to 2.8.0) on 2026-07-13, which added URI scheme validation to reject non-HTTP(S) schemes (file://, ftp://, data:, etc.) before any fetch operation. While the version number was later reverted from 2.8.0.post2+tuxcare to 2.8.0.pos...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-48522: PyJWKClient URI scheme SSRF vulnerability is already fixed in the target repository. The fix was introduced via commit 67029b7 (Backport CVE-2026-48526 to 2.8.0) on 2026-07-13, which added URI scheme validation to reject non-HTTP(S) schemes (file://, ftp://, data:, etc.) before any fetch operation. While the version number was later reverted from 2.8.0.post2+tuxcare to 2.8.0.pos..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 is fixed in version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48524"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 does not affect version 2.8.0.post4+tuxcare of pyjwt. pyjwt 2.8.0 is not affected by CVE-2026-48525. The upstream fix (jpadilla/pyjwt@95791b1) forwards the opt-in 'enforce_minimum_key_length' option into sig_options in api_jwt.py; the vulnerability is that setting that option per call had no effect, letting an undersized RSA key through. Branch tuxcare-current/2.8.0 contains none of that machinery (no enforce_minimum_key_length, no sig_options, no InsecureKeyLengthWarning in jwt/). The CVE-2025-45768 backport (796cc35, PYELSCVE-180) instead enforces a minimum 2048-bit RSA key unconditionally in RSAAlgorithm.prepare_key, which no option can disable. Verified on the released 2.8.0.post3+tuxcare wheel from Nexus with a fresh 1024-bit RSA key: rejected with no options, with enforce_minimum_key_length=False and with verify_signature=False; a 2048-bit key still round-trips. MR !18 was changelog-only and has been closed. Jira PYELSCVE-1216.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48525"
      },
      "impact_statement": "pyjwt 2.8.0 is not affected by CVE-2026-48525. The upstream fix (jpadilla/pyjwt@95791b1) forwards the opt-in 'enforce_minimum_key_length' option into sig_options in api_jwt.py; the vulnerability is that setting that option per call had no effect, letting an undersized RSA key through. Branch tuxcare-current/2.8.0 contains none of that machinery (no enforce_minimum_key_length, no sig_options, no InsecureKeyLengthWarning in jwt/). The CVE-2025-45768 backport (796cc35, PYELSCVE-180) instead enforces a minimum 2048-bit RSA key unconditionally in RSAAlgorithm.prepare_key, which no option can disable. Verified on the released 2.8.0.post3+tuxcare wheel from Nexus with a fresh 1024-bit RSA key: rejected with no options, with enforce_minimum_key_length=False and with verify_signature=False; a 2048-bit key still round-trips. MR !18 was changelog-only and has been closed. Jira PYELSCVE-1216."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.8.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 2.8.0.post4+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post5+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post5+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 5.1.1.post5+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2022-41323"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.post5+tuxcare of django, and is fixed in 5.1.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.post5+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "action_statement": "Vulnerability CVE-2024-41990 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post4+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post4+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post4+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.post4+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 is fixed in version 5.1.1.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 5.1.1.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 5.1.1.post3+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      },
      "action_statement": "Vulnerability CVE-2025-67724 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      },
      "action_statement": "Vulnerability CVE-2025-67725 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      },
      "action_statement": "Vulnerability CVE-2025-67726 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      },
      "action_statement": "Vulnerability CVE-2026-31958 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      },
      "action_statement": "Vulnerability CVE-2026-35536 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      },
      "action_statement": "Vulnerability CVE-2026-49853 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      },
      "action_statement": "Vulnerability CVE-2026-49854 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      },
      "action_statement": "Vulnerability CVE-2026-49855 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      },
      "action_statement": "Vulnerability CVE-2026-82397 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      },
      "action_statement": "Vulnerability GHSA-753j-mpmx-qq6g affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      },
      "action_statement": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      },
      "action_statement": "Vulnerability GHSA-8423-8fgw-73vq affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      },
      "action_statement": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      },
      "action_statement": "Vulnerability GHSA-qppv-j76h-2rpx affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      },
      "action_statement": "Vulnerability GHSA-w235-7p84-xx57 affects version 5.1.1.post3+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post14+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post14+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post14+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post14+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post14+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post14+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post14+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post14+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post14+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post14+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post14+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post14+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.post14+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post8+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post8+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.post8+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      },
      "action_statement": "Vulnerability CVE-2024-27351 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      },
      "action_statement": "Vulnerability CVE-2024-39329 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      },
      "action_statement": "Vulnerability CVE-2024-39330 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      },
      "action_statement": "Vulnerability CVE-2024-41989 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "action_statement": "Vulnerability CVE-2024-41990 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      },
      "action_statement": "Vulnerability CVE-2024-41991 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      },
      "action_statement": "Vulnerability CVE-2024-42005 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      },
      "action_statement": "Vulnerability CVE-2024-45230 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      },
      "action_statement": "Vulnerability CVE-2024-45231 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      },
      "action_statement": "Vulnerability CVE-2024-53907 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      },
      "action_statement": "Vulnerability CVE-2024-53908 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      },
      "action_statement": "Vulnerability CVE-2024-56374 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      },
      "action_statement": "Vulnerability CVE-2025-13473 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      },
      "action_statement": "Vulnerability CVE-2025-26699 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      },
      "action_statement": "Vulnerability CVE-2025-27556 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      },
      "action_statement": "Vulnerability CVE-2025-48432 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      },
      "action_statement": "Vulnerability CVE-2025-57833 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      },
      "action_statement": "Vulnerability CVE-2025-64458 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      },
      "action_statement": "Vulnerability CVE-2025-64459 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      },
      "action_statement": "Vulnerability CVE-2025-64460 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      },
      "action_statement": "Vulnerability CVE-2026-1207 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post3+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post3+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      },
      "action_statement": "Vulnerability CVE-2026-1287 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      },
      "action_statement": "Vulnerability CVE-2026-1312 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      },
      "action_statement": "Vulnerability CVE-2026-48587 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      },
      "action_statement": "Vulnerability CVE-2026-48588 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      },
      "action_statement": "Vulnerability CVE-2026-53877 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post3+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      },
      "action_statement": "Vulnerability CVE-2026-6873 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      },
      "action_statement": "Vulnerability CVE-2026-8404 affects version 5.0.post3+tuxcare of django, and is fixed in 5.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 5.1.1.post6+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-24680"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41990"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.0.post15+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 affects version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      },
      "action_statement": "Vulnerability CVE-2025-14550 affects version 5.0.post15+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.post15+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.post15+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.post15+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.post15+tuxcare of django, and is fixed in 5.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.post15+tuxcare of django, and is fixed in 5.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.post15+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:02:14.420070+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.post15+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      },
      "action_statement": "Vulnerability CVE-2023-28370 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      },
      "action_statement": "Vulnerability CVE-2025-67724 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      },
      "action_statement": "Vulnerability CVE-2025-67725 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-25T03:25:31.426299+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      },
      "action_statement": "Vulnerability CVE-2025-67726 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      },
      "action_statement": "Vulnerability CVE-2026-82397 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      },
      "action_statement": "Vulnerability GHSA-8423-8fgw-73vq affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T05:10:00.146465+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:38:16.308362+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 6.1.0.post4+tuxcare of tornado, and is fixed in 6.1.0.post10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post4+tuxcare of tornado.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 affects version 5.1.4.post6+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      },
      "action_statement": "Vulnerability CVE-2025-13372 affects version 5.1.4.post6+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 affects version 5.1.4.post6+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      },
      "action_statement": "Vulnerability CVE-2025-59682 affects version 5.1.4.post6+tuxcare of django, and is fixed in 5.1.4.post7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.4.post6+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.4.post6+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.4.post6+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.4.post6+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.4.post6+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.1.4.post7+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.1.4.post7+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.1.4.post7+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.1.4.post7+tuxcare of django, and is fixed in 5.1.4.post8+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.4.post7+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-32873 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-32873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-59681 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-59682 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-59682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53878"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.1.4.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.1.4.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T08:48:43.786965+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.1.4.post8+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28370 is fixed in version 5.1.1.post2+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2023-28370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52804 is fixed in version 5.1.1.post2+tuxcare of tornado.",
      "vulnerability": {
        "name": "CVE-2024-52804"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47287 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-47287"
      },
      "action_statement": "Vulnerability CVE-2025-47287 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67724 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67724"
      },
      "action_statement": "Vulnerability CVE-2025-67724 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67725 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67725"
      },
      "action_statement": "Vulnerability CVE-2025-67725 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2025-67726 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-67726"
      },
      "action_statement": "Vulnerability CVE-2025-67726 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-31958 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31958"
      },
      "action_statement": "Vulnerability CVE-2026-31958 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-35536 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-35536"
      },
      "action_statement": "Vulnerability CVE-2026-35536 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49853 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49853"
      },
      "action_statement": "Vulnerability CVE-2026-49853 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49854 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49854"
      },
      "action_statement": "Vulnerability CVE-2026-49854 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability CVE-2026-49855 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49855"
      },
      "action_statement": "Vulnerability CVE-2026-49855 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability CVE-2026-82397 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82397"
      },
      "action_statement": "Vulnerability CVE-2026-82397 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3hv7-mjh2-fv65"
      },
      "action_statement": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-753j-mpmx-qq6g affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-753j-mpmx-qq6g"
      },
      "action_statement": "Vulnerability GHSA-753j-mpmx-qq6g affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-78cv-mqj4-43f7"
      },
      "action_statement": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:50:05.718035+00:00",
      "status_notes": "Vulnerability GHSA-8423-8fgw-73vq affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8423-8fgw-73vq"
      },
      "action_statement": "Vulnerability GHSA-8423-8fgw-73vq affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T06:33:27.266844+00:00",
      "status_notes": "Vulnerability GHSA-c2m8-h5v5-343r affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-c2m8-h5v5-343r"
      },
      "action_statement": "Vulnerability GHSA-c2m8-h5v5-343r affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T09:09:01.183793+00:00",
      "status_notes": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-chx6-46f5-w4vp"
      },
      "action_statement": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-pw6j-qg29-8w7f"
      },
      "action_statement": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-qppv-j76h-2rpx affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-qppv-j76h-2rpx"
      },
      "action_statement": "Vulnerability GHSA-qppv-j76h-2rpx affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/tornado@5.1.1.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/tornado@5.1.1.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T09:44:50.265994+00:00",
      "status_notes": "Vulnerability GHSA-w235-7p84-xx57 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-w235-7p84-xx57"
      },
      "action_statement": "Vulnerability GHSA-w235-7p84-xx57 affects version 5.1.1.post2+tuxcare of tornado, and is fixed in 5.1.1.post4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/sentence-transformers@2.7.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/sentence-transformers@2.7.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10370 is fixed in version 2.7.0.post1+tuxcare of sentence-transformers.",
      "vulnerability": {
        "name": "AIKIDO-2024-10370"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/sentence-transformers@2.7.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/sentence-transformers@2.7.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T10:48:20.051130+00:00",
      "status_notes": "Vulnerability CVE-2026-68770 affects version 2.7.0.post1+tuxcare of sentence-transformers, and is fixed in 2.7.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-68770"
      },
      "action_statement": "Vulnerability CVE-2026-68770 affects version 2.7.0.post1+tuxcare of sentence-transformers, and is fixed in 2.7.0.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/sentence-transformers@2.7.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/sentence-transformers@2.7.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T10:48:20.051130+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10370 is fixed in version 2.7.0.post3+tuxcare of sentence-transformers.",
      "vulnerability": {
        "name": "AIKIDO-2024-10370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/sentence-transformers@2.7.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/sentence-transformers@2.7.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T10:48:20.051130+00:00",
      "status_notes": "Vulnerability CVE-2026-68770 is fixed in version 2.7.0.post3+tuxcare of sentence-transformers.",
      "vulnerability": {
        "name": "CVE-2026-68770"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2025-45768 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2025-45768"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-101917 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101917"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-101918 affects version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-101918"
      },
      "action_statement": "Vulnerability CVE-2026-101918 affects version 2.10.1.post5+tuxcare of pyjwt."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-102267 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102268 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102268"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102269 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102269"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102270 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102270"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:35:00.185365+00:00",
      "status_notes": "Vulnerability CVE-2026-102271 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-102274 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-102274"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-32597 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-32597"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-48522 does not affect version 2.10.1.post5+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48522"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-48523 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48523"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-48524 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48524"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-48525 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48525"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyjwt@2.10.1.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T07:31:00.118390+00:00",
      "status_notes": "Vulnerability CVE-2026-48526 is fixed in version 2.10.1.post5+tuxcare of pyjwt.",
      "vulnerability": {
        "name": "CVE-2026-48526"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10495 is fixed in version 20.39.1.post1+tuxcare of virtualenv.",
      "vulnerability": {
        "name": "AIKIDO-2026-10495"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102925 affects version 20.39.1.post1+tuxcare of virtualenv.",
      "vulnerability": {
        "name": "CVE-2026-102925"
      },
      "action_statement": "Vulnerability CVE-2026-102925 affects version 20.39.1.post1+tuxcare of virtualenv."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T00:04:00.303221+00:00",
      "status_notes": "Vulnerability CVE-2026-102930 affects version 20.39.1.post1+tuxcare of virtualenv.",
      "vulnerability": {
        "name": "CVE-2026-102930"
      },
      "action_statement": "Vulnerability CVE-2026-102930 affects version 20.39.1.post1+tuxcare of virtualenv."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102937 affects version 20.39.1.post1+tuxcare of virtualenv.",
      "vulnerability": {
        "name": "CVE-2026-102937"
      },
      "action_statement": "Vulnerability CVE-2026-102937 affects version 20.39.1.post1+tuxcare of virtualenv."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T00:04:00.303221+00:00",
      "status_notes": "Vulnerability CVE-2026-102938 affects version 20.39.1.post1+tuxcare of virtualenv.",
      "vulnerability": {
        "name": "CVE-2026-102938"
      },
      "action_statement": "Vulnerability CVE-2026-102938 affects version 20.39.1.post1+tuxcare of virtualenv."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      },
      "action_statement": "Vulnerability CVE-2026-54530 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      },
      "action_statement": "Vulnerability CVE-2026-54531 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      },
      "action_statement": "Vulnerability CVE-2026-54651 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post9+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post9+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post9+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      },
      "action_statement": "Vulnerability CVE-2026-48155 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      },
      "action_statement": "Vulnerability CVE-2026-49461 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      },
      "action_statement": "Vulnerability CVE-2026-54530 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      },
      "action_statement": "Vulnerability CVE-2026-54531 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      },
      "action_statement": "Vulnerability CVE-2026-54651 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post7+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post7+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      },
      "action_statement": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post7+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post12+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post12+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post12+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post12+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p is fixed in version 5.9.0.post12+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post11+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post11+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post11+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      },
      "action_statement": "Vulnerability CVE-2026-48155 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      },
      "action_statement": "Vulnerability CVE-2026-54530 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      },
      "action_statement": "Vulnerability CVE-2026-54531 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      },
      "action_statement": "Vulnerability CVE-2026-54651 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post8+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post8+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      },
      "action_statement": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post8+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      },
      "action_statement": "Vulnerability CVE-2026-41168 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      },
      "action_statement": "Vulnerability CVE-2026-41312 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      },
      "action_statement": "Vulnerability CVE-2026-41314 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      },
      "action_statement": "Vulnerability CVE-2026-48155 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      },
      "action_statement": "Vulnerability CVE-2026-48156 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      },
      "action_statement": "Vulnerability CVE-2026-49460 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      },
      "action_statement": "Vulnerability CVE-2026-49461 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      },
      "action_statement": "Vulnerability CVE-2026-54530 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      },
      "action_statement": "Vulnerability CVE-2026-54531 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      },
      "action_statement": "Vulnerability CVE-2026-54651 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post5+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post5+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      },
      "action_statement": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post5+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      },
      "action_statement": "Vulnerability CVE-2026-48155 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      },
      "action_statement": "Vulnerability CVE-2026-48156 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      },
      "action_statement": "Vulnerability CVE-2026-49460 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      },
      "action_statement": "Vulnerability CVE-2026-49461 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      },
      "action_statement": "Vulnerability CVE-2026-54530 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      },
      "action_statement": "Vulnerability CVE-2026-54531 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      },
      "action_statement": "Vulnerability CVE-2026-54651 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post6+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post6+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      },
      "action_statement": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post6+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      },
      "action_statement": "Vulnerability CVE-2026-41168 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      },
      "action_statement": "Vulnerability CVE-2026-41312 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      },
      "action_statement": "Vulnerability CVE-2026-41313 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      },
      "action_statement": "Vulnerability CVE-2026-41314 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      },
      "action_statement": "Vulnerability CVE-2026-48155 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      },
      "action_statement": "Vulnerability CVE-2026-48156 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      },
      "action_statement": "Vulnerability CVE-2026-49460 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      },
      "action_statement": "Vulnerability CVE-2026-49461 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      },
      "action_statement": "Vulnerability CVE-2026-54530 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      },
      "action_statement": "Vulnerability CVE-2026-54531 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      },
      "action_statement": "Vulnerability CVE-2026-54651 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post4+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post4+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      },
      "action_statement": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post4+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post13+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post13+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post13+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post13+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p is fixed in version 5.9.0.post13+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      },
      "action_statement": "Vulnerability CVE-2025-62708 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      },
      "action_statement": "Vulnerability CVE-2026-27628 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      },
      "action_statement": "Vulnerability CVE-2026-41168 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      },
      "action_statement": "Vulnerability CVE-2026-41312 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      },
      "action_statement": "Vulnerability CVE-2026-41313 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      },
      "action_statement": "Vulnerability CVE-2026-41314 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      },
      "action_statement": "Vulnerability CVE-2026-48155 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      },
      "action_statement": "Vulnerability CVE-2026-48156 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      },
      "action_statement": "Vulnerability CVE-2026-49460 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      },
      "action_statement": "Vulnerability CVE-2026-49461 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      },
      "action_statement": "Vulnerability CVE-2026-54530 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      },
      "action_statement": "Vulnerability CVE-2026-54531 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      },
      "action_statement": "Vulnerability CVE-2026-54651 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post2+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post2+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      },
      "action_statement": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post2+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post14+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post14+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post14+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post14+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p is fixed in version 5.9.0.post14+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      },
      "action_statement": "Vulnerability CVE-2025-62707 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      },
      "action_statement": "Vulnerability CVE-2025-62708 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      },
      "action_statement": "Vulnerability CVE-2026-27628 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      },
      "action_statement": "Vulnerability CVE-2026-41168 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      },
      "action_statement": "Vulnerability CVE-2026-41312 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      },
      "action_statement": "Vulnerability CVE-2026-41313 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      },
      "action_statement": "Vulnerability CVE-2026-41314 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      },
      "action_statement": "Vulnerability CVE-2026-48155 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      },
      "action_statement": "Vulnerability CVE-2026-48156 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      },
      "action_statement": "Vulnerability CVE-2026-49460 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      },
      "action_statement": "Vulnerability CVE-2026-49461 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      },
      "action_statement": "Vulnerability CVE-2026-54530 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      },
      "action_statement": "Vulnerability CVE-2026-54531 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      },
      "action_statement": "Vulnerability CVE-2026-54651 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post1+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post1+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      },
      "action_statement": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post1+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      },
      "action_statement": "Vulnerability CVE-2026-54651 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post10+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post10+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post10+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      },
      "action_statement": "Vulnerability CVE-2026-27628 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      },
      "action_statement": "Vulnerability CVE-2026-31826 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      },
      "action_statement": "Vulnerability CVE-2026-41168 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      },
      "action_statement": "Vulnerability CVE-2026-41312 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      },
      "action_statement": "Vulnerability CVE-2026-41313 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      },
      "action_statement": "Vulnerability CVE-2026-41314 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      },
      "action_statement": "Vulnerability CVE-2026-48155 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      },
      "action_statement": "Vulnerability CVE-2026-48156 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      },
      "action_statement": "Vulnerability CVE-2026-48735 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      },
      "action_statement": "Vulnerability CVE-2026-49460 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      },
      "action_statement": "Vulnerability CVE-2026-49461 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      },
      "action_statement": "Vulnerability CVE-2026-54530 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      },
      "action_statement": "Vulnerability CVE-2026-54531 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      },
      "action_statement": "Vulnerability CVE-2026-54651 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      },
      "action_statement": "Vulnerability CVE-2026-59935 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      },
      "action_statement": "Vulnerability CVE-2026-59936 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      },
      "action_statement": "Vulnerability CVE-2026-59937 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      },
      "action_statement": "Vulnerability CVE-2026-59938 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      },
      "action_statement": "Vulnerability CVE-2026-71852 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      },
      "action_statement": "Vulnerability CVE-2026-71870 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post3+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post3+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      },
      "action_statement": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      },
      "action_statement": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post3+tuxcare of pypdf, and is fixed in 5.9.0.post12+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post16+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post16+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post16+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post16+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p is fixed in version 5.9.0.post16+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post17+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post17+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post17+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p is fixed in version 5.9.0.post17+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-55197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62707"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2025-62708"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66019 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-66019"
      },
      "action_statement": "Vulnerability CVE-2025-66019 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102993 affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102993"
      },
      "action_statement": "Vulnerability CVE-2026-102993 affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102994 affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102994"
      },
      "action_statement": "Vulnerability CVE-2026-102994 affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102995 affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102995"
      },
      "action_statement": "Vulnerability CVE-2026-102995 affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102996 affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102996"
      },
      "action_statement": "Vulnerability CVE-2026-102996 affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102997 affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102997"
      },
      "action_statement": "Vulnerability CVE-2026-102997 affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-102998 affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102998"
      },
      "action_statement": "Vulnerability CVE-2026-102998 affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:20:13.103592+00:00",
      "status_notes": "Vulnerability CVE-2026-102999 affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-102999"
      },
      "action_statement": "Vulnerability CVE-2026-102999 affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T15:14:19.367434+00:00",
      "status_notes": "Vulnerability CVE-2026-103000 affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-103000"
      },
      "action_statement": "Vulnerability CVE-2026-103000 affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22690 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22690"
      },
      "action_statement": "Vulnerability CVE-2026-22690 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22691 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22691"
      },
      "action_statement": "Vulnerability CVE-2026-22691 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24688 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24688"
      },
      "action_statement": "Vulnerability CVE-2026-24688 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27024 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27024"
      },
      "action_statement": "Vulnerability CVE-2026-27024 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27025 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27025"
      },
      "action_statement": "Vulnerability CVE-2026-27025 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27026 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27026"
      },
      "action_statement": "Vulnerability CVE-2026-27026 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-27628"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27888 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27888"
      },
      "action_statement": "Vulnerability CVE-2026-27888 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28351 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28351"
      },
      "action_statement": "Vulnerability CVE-2026-28351 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28804 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28804"
      },
      "action_statement": "Vulnerability CVE-2026-28804 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31826 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-31826"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33123 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33123"
      },
      "action_statement": "Vulnerability CVE-2026-33123 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33699 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33699"
      },
      "action_statement": "Vulnerability CVE-2026-33699 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40260 affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-40260"
      },
      "action_statement": "Vulnerability CVE-2026-40260 affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-41314"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48155"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48156"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48735 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-48735"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-49461"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54530 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54531 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54651 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-54651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-57204 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-57204"
      },
      "action_statement": "Vulnerability CVE-2026-57204 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post16+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59935 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59935"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59936 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59936"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59937 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59937"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59938 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-59938"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71852 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71852"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71870 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "CVE-2026-71870"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82398 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-82398"
      },
      "action_statement": "Vulnerability CVE-2026-82398 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84309 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84309"
      },
      "action_statement": "Vulnerability CVE-2026-84309 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84310 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84310"
      },
      "action_statement": "Vulnerability CVE-2026-84310 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84311 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-84311"
      },
      "action_statement": "Vulnerability CVE-2026-84311 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-4pxv-j86v-mhcw"
      },
      "action_statement": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-7gw9-cf7v-778f"
      },
      "action_statement": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9m86-7pmv-2852"
      },
      "action_statement": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post15+tuxcare of pypdf, and is fixed in 5.9.0.post17+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jj6c-8h6c-hppx"
      },
      "action_statement": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post15+tuxcare of pypdf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-jm82-fx9c-mx94"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pypdf@5.9.0.post15+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pypdf@5.9.0.post15+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x284-j5p8-9c5p is fixed in version 5.9.0.post15+tuxcare of pypdf.",
      "vulnerability": {
        "name": "GHSA-x284-j5p8-9c5p"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@25.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@25.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:34:24.527770+00:00",
      "status_notes": "Vulnerability CVE-2026-27448 is fixed in version 25.3.0.post2+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27448"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@25.3.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@25.3.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:34:24.527770+00:00",
      "status_notes": "Vulnerability CVE-2026-27459 is fixed in version 25.3.0.post2+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@24.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@24.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-27448 is fixed in version 24.3.0.post3+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27448"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/pyopenssl@24.3.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/pyopenssl@24.3.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-27459 is fixed in version 24.3.0.post3+tuxcare of pyopenssl.",
      "vulnerability": {
        "name": "CVE-2026-27459"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2024-3660 affects version 2.15.0.post2+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-3660"
      },
      "action_statement": "Vulnerability CVE-2024-3660 affects version 2.15.0.post2+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55459 affects version 2.15.0.post2+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2024-55459"
      },
      "action_statement": "Vulnerability CVE-2024-55459 affects version 2.15.0.post2+tuxcare of keras."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-12058 affects version 2.15.0.post2+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2025-12058"
      },
      "action_statement": "Vulnerability CVE-2025-12058 affects version 2.15.0.post2+tuxcare of keras."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-12060 is fixed in version 2.15.0.post2+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2025-12060"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T07:36:45.696691+00:00",
      "status_notes": "Vulnerability CVE-2025-9906 does not affect version 2.15.0.post2+tuxcare of keras. keras 2.15.0: vulnerable API (keras.config.enable_unsafe_deserialization / KerasSaveable, keras 3.0-3.10) absent in 2.x; malicious .keras gadget fails with TypeError. esultanaliev 2026-10-02",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-9906"
      },
      "impact_statement": "keras 2.15.0: vulnerable API (keras.config.enable_unsafe_deserialization / KerasSaveable, keras 3.0-3.10) absent in 2.x; malicious .keras gadget fails with TypeError. esultanaliev 2026-10-02"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T07:39:18.543267+00:00",
      "status_notes": "Vulnerability CVE-2026-0897 does not affect version 2.15.0.post2+tuxcare of keras. keras 2.15.0: fix is in KerasFileEditor (keras/src/saving/file_editor.py), module absent in 2.x. esultanaliev 2026-10-02",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0897"
      },
      "impact_statement": "keras 2.15.0: fix is in KerasFileEditor (keras/src/saving/file_editor.py), module absent in 2.x. esultanaliev 2026-10-02"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-11816 affects version 2.15.0.post2+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-11816"
      },
      "action_statement": "Vulnerability CVE-2026-11816 affects version 2.15.0.post2+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-12479 affects version 2.15.0.post2+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12479"
      },
      "action_statement": "Vulnerability CVE-2026-12479 affects version 2.15.0.post2+tuxcare of keras."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-12480 affects version 2.15.0.post2+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12480"
      },
      "action_statement": "Vulnerability CVE-2026-12480 affects version 2.15.0.post2+tuxcare of keras."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-12481 affects version 2.15.0.post2+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-12481"
      },
      "action_statement": "Vulnerability CVE-2026-12481 affects version 2.15.0.post2+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-12482 affects version 2.15.0.post2+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12482"
      },
      "action_statement": "Vulnerability CVE-2026-12482 affects version 2.15.0.post2+tuxcare of keras."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T07:39:18.543267+00:00",
      "status_notes": "Vulnerability CVE-2026-12484 does not affect version 2.15.0.post2+tuxcare of keras. keras 2.15.0: TorchModuleWrapper absent in 2.x (TF-only). esultanaliev 2026-10-02",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-12484"
      },
      "impact_statement": "keras 2.15.0: TorchModuleWrapper absent in 2.x (TF-only). esultanaliev 2026-10-02"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-12570 affects version 2.15.0.post2+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12570"
      },
      "action_statement": "Vulnerability CVE-2026-12570 affects version 2.15.0.post2+tuxcare of keras."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1462 does not affect version 2.15.0.post2+tuxcare of keras. Not applicable to keras 2.15.0: TFSMLayer was introduced in Keras 3.x; class and file (keras/src/export/tfsm_layer.py) do not exist in 2.x line. Per NVD, scoped to keras 3.13.0. Ref: https://nvd.nist.gov/vuln/detail/CVE-2026-1462",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-1462"
      },
      "impact_statement": "Not applicable to keras 2.15.0: TFSMLayer was introduced in Keras 3.x; class and file (keras/src/export/tfsm_layer.py) do not exist in 2.x line. Per NVD, scoped to keras 3.13.0. Ref: https://nvd.nist.gov/vuln/detail/CVE-2026-1462"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9335 affects version 2.15.0.post2+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-9335"
      },
      "action_statement": "Vulnerability CVE-2026-9335 affects version 2.15.0.post2+tuxcare of keras."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/h11@0.12.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/h11@0.12.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:22:55.479914+00:00",
      "status_notes": "Vulnerability CVE-2025-43859 is fixed in version 0.12.0.post1+tuxcare of h11.",
      "vulnerability": {
        "name": "CVE-2025-43859"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2024-3660 is fixed in version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2024-3660"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2024-55459 affects version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2024-55459"
      },
      "action_statement": "Vulnerability CVE-2024-55459 affects version 2.15.0.post3+tuxcare of keras."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2025-12058 affects version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2025-12058"
      },
      "action_statement": "Vulnerability CVE-2025-12058 affects version 2.15.0.post3+tuxcare of keras."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2025-12060 is fixed in version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2025-12060"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2025-9906 does not affect version 2.15.0.post3+tuxcare of keras. keras 2.15.0: vulnerable API (keras.config.enable_unsafe_deserialization / KerasSaveable, keras 3.0-3.10) absent in 2.x; malicious .keras gadget fails with TypeError. esultanaliev 2026-10-02",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-9906"
      },
      "impact_statement": "keras 2.15.0: vulnerable API (keras.config.enable_unsafe_deserialization / KerasSaveable, keras 3.0-3.10) absent in 2.x; malicious .keras gadget fails with TypeError. esultanaliev 2026-10-02"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-0897 does not affect version 2.15.0.post3+tuxcare of keras. keras 2.15.0: fix is in KerasFileEditor (keras/src/saving/file_editor.py), module absent in 2.x. esultanaliev 2026-10-02",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0897"
      },
      "impact_statement": "keras 2.15.0: fix is in KerasFileEditor (keras/src/saving/file_editor.py), module absent in 2.x. esultanaliev 2026-10-02"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-11816 is fixed in version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-11816"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-12479 affects version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12479"
      },
      "action_statement": "Vulnerability CVE-2026-12479 affects version 2.15.0.post3+tuxcare of keras."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-12480 affects version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12480"
      },
      "action_statement": "Vulnerability CVE-2026-12480 affects version 2.15.0.post3+tuxcare of keras."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-12481 is fixed in version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12481"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-12482 affects version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12482"
      },
      "action_statement": "Vulnerability CVE-2026-12482 affects version 2.15.0.post3+tuxcare of keras."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-12484 does not affect version 2.15.0.post3+tuxcare of keras. keras 2.15.0: TorchModuleWrapper absent in 2.x (TF-only). esultanaliev 2026-10-02",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-12484"
      },
      "impact_statement": "keras 2.15.0: TorchModuleWrapper absent in 2.x (TF-only). esultanaliev 2026-10-02"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-12570 affects version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12570"
      },
      "action_statement": "Vulnerability CVE-2026-12570 affects version 2.15.0.post3+tuxcare of keras."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-1462 does not affect version 2.15.0.post3+tuxcare of keras. Not applicable to keras 2.15.0: TFSMLayer was introduced in Keras 3.x; class and file (keras/src/export/tfsm_layer.py) do not exist in 2.x line. Per NVD, scoped to keras 3.13.0. Ref: https://nvd.nist.gov/vuln/detail/CVE-2026-1462",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-1462"
      },
      "impact_statement": "Not applicable to keras 2.15.0: TFSMLayer was introduced in Keras 3.x; class and file (keras/src/export/tfsm_layer.py) do not exist in 2.x line. Per NVD, scoped to keras 3.13.0. Ref: https://nvd.nist.gov/vuln/detail/CVE-2026-1462"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-9335 affects version 2.15.0.post3+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-9335"
      },
      "action_statement": "Vulnerability CVE-2026-9335 affects version 2.15.0.post3+tuxcare of keras."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2024-3660 affects version 2.15.0.post1+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-3660"
      },
      "action_statement": "Vulnerability CVE-2024-3660 affects version 2.15.0.post1+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55459 affects version 2.15.0.post1+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2024-55459"
      },
      "action_statement": "Vulnerability CVE-2024-55459 affects version 2.15.0.post1+tuxcare of keras."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-12058 affects version 2.15.0.post1+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2025-12058"
      },
      "action_statement": "Vulnerability CVE-2025-12058 affects version 2.15.0.post1+tuxcare of keras."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-12060 affects version 2.15.0.post1+tuxcare of keras, and is fixed in 2.15.0.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-12060"
      },
      "action_statement": "Vulnerability CVE-2025-12060 affects version 2.15.0.post1+tuxcare of keras, and is fixed in 2.15.0.post2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T07:36:45.696691+00:00",
      "status_notes": "Vulnerability CVE-2025-9906 does not affect version 2.15.0.post1+tuxcare of keras. keras 2.15.0: vulnerable API (keras.config.enable_unsafe_deserialization / KerasSaveable, keras 3.0-3.10) absent in 2.x; malicious .keras gadget fails with TypeError. esultanaliev 2026-10-02",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-9906"
      },
      "impact_statement": "keras 2.15.0: vulnerable API (keras.config.enable_unsafe_deserialization / KerasSaveable, keras 3.0-3.10) absent in 2.x; malicious .keras gadget fails with TypeError. esultanaliev 2026-10-02"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T07:39:18.543267+00:00",
      "status_notes": "Vulnerability CVE-2026-0897 does not affect version 2.15.0.post1+tuxcare of keras. keras 2.15.0: fix is in KerasFileEditor (keras/src/saving/file_editor.py), module absent in 2.x. esultanaliev 2026-10-02",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-0897"
      },
      "impact_statement": "keras 2.15.0: fix is in KerasFileEditor (keras/src/saving/file_editor.py), module absent in 2.x. esultanaliev 2026-10-02"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-11816 affects version 2.15.0.post1+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-11816"
      },
      "action_statement": "Vulnerability CVE-2026-11816 affects version 2.15.0.post1+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-12479 affects version 2.15.0.post1+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12479"
      },
      "action_statement": "Vulnerability CVE-2026-12479 affects version 2.15.0.post1+tuxcare of keras."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-12480 affects version 2.15.0.post1+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12480"
      },
      "action_statement": "Vulnerability CVE-2026-12480 affects version 2.15.0.post1+tuxcare of keras."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T08:02:59.966216+00:00",
      "status_notes": "Vulnerability CVE-2026-12481 affects version 2.15.0.post1+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-12481"
      },
      "action_statement": "Vulnerability CVE-2026-12481 affects version 2.15.0.post1+tuxcare of keras, and is fixed in 2.15.0.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-12482 affects version 2.15.0.post1+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12482"
      },
      "action_statement": "Vulnerability CVE-2026-12482 affects version 2.15.0.post1+tuxcare of keras."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T07:39:18.543267+00:00",
      "status_notes": "Vulnerability CVE-2026-12484 does not affect version 2.15.0.post1+tuxcare of keras. keras 2.15.0: TorchModuleWrapper absent in 2.x (TF-only). esultanaliev 2026-10-02",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-12484"
      },
      "impact_statement": "keras 2.15.0: TorchModuleWrapper absent in 2.x (TF-only). esultanaliev 2026-10-02"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-12570 affects version 2.15.0.post1+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-12570"
      },
      "action_statement": "Vulnerability CVE-2026-12570 affects version 2.15.0.post1+tuxcare of keras."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1462 does not affect version 2.15.0.post1+tuxcare of keras. Not applicable to keras 2.15.0: TFSMLayer was introduced in Keras 3.x; class and file (keras/src/export/tfsm_layer.py) do not exist in 2.x line. Per NVD, scoped to keras 3.13.0. Ref: https://nvd.nist.gov/vuln/detail/CVE-2026-1462",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-1462"
      },
      "impact_statement": "Not applicable to keras 2.15.0: TFSMLayer was introduced in Keras 3.x; class and file (keras/src/export/tfsm_layer.py) do not exist in 2.x line. Per NVD, scoped to keras 3.13.0. Ref: https://nvd.nist.gov/vuln/detail/CVE-2026-1462"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/keras@2.15.0.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9335 affects version 2.15.0.post1+tuxcare of keras.",
      "vulnerability": {
        "name": "CVE-2026-9335"
      },
      "action_statement": "Vulnerability CVE-2026-9335 affects version 2.15.0.post1+tuxcare of keras."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post3+tuxcare of dulwich.",
      "vulnerability": {
        "name": "AIKIDO-2026-10554"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42305 is fixed in version 0.25.2.post3+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-42305"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42563 is fixed in version 0.25.2.post3+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-42563"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47712 affects version 0.25.2.post3+tuxcare of dulwich, and is fixed in 0.25.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47712"
      },
      "action_statement": "Vulnerability CVE-2026-47712 affects version 0.25.2.post3+tuxcare of dulwich, and is fixed in 0.25.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47734 affects version 0.25.2.post3+tuxcare of dulwich, and is fixed in 0.25.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47734"
      },
      "action_statement": "Vulnerability CVE-2026-47734 affects version 0.25.2.post3+tuxcare of dulwich, and is fixed in 0.25.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-52726 affects version 0.25.2.post3+tuxcare of dulwich, and is fixed in 0.25.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-52726"
      },
      "action_statement": "Vulnerability CVE-2026-52726 affects version 0.25.2.post3+tuxcare of dulwich, and is fixed in 0.25.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post3+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-35mr-4567-66vg"
      },
      "action_statement": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post3+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post3+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-5fqc-mrg8-w798"
      },
      "action_statement": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post3+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:19:00.191036+00:00",
      "status_notes": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post3+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8mcx-5rqc-vhmf"
      },
      "action_statement": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post3+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post3+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8w8g-wq8h-fq33"
      },
      "action_statement": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post3+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T18:58:00.304965+00:00",
      "status_notes": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post3+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-cm62-gvxx-vmxx"
      },
      "action_statement": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post3+tuxcare of dulwich."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post5+tuxcare of dulwich.",
      "vulnerability": {
        "name": "AIKIDO-2026-10554"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42305 is fixed in version 0.25.2.post5+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-42305"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42563 is fixed in version 0.25.2.post5+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-42563"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47712 affects version 0.25.2.post5+tuxcare of dulwich, and is fixed in 0.25.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47712"
      },
      "action_statement": "Vulnerability CVE-2026-47712 affects version 0.25.2.post5+tuxcare of dulwich, and is fixed in 0.25.2.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47734 is fixed in version 0.25.2.post5+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-47734"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-52726 is fixed in version 0.25.2.post5+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-52726"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post5+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-35mr-4567-66vg"
      },
      "action_statement": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post5+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post5+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-5fqc-mrg8-w798"
      },
      "action_statement": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post5+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:19:00.191036+00:00",
      "status_notes": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post5+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8mcx-5rqc-vhmf"
      },
      "action_statement": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post5+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post5+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8w8g-wq8h-fq33"
      },
      "action_statement": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post5+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T18:58:00.304965+00:00",
      "status_notes": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post5+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-cm62-gvxx-vmxx"
      },
      "action_statement": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post5+tuxcare of dulwich."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post1+tuxcare of dulwich.",
      "vulnerability": {
        "name": "AIKIDO-2026-10554"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42305 affects version 0.25.2.post1+tuxcare of dulwich, and is fixed in 0.25.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42305"
      },
      "action_statement": "Vulnerability CVE-2026-42305 affects version 0.25.2.post1+tuxcare of dulwich, and is fixed in 0.25.2.post3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42563 affects version 0.25.2.post1+tuxcare of dulwich, and is fixed in 0.25.2.post2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42563"
      },
      "action_statement": "Vulnerability CVE-2026-42563 affects version 0.25.2.post1+tuxcare of dulwich, and is fixed in 0.25.2.post2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47712 affects version 0.25.2.post1+tuxcare of dulwich, and is fixed in 0.25.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47712"
      },
      "action_statement": "Vulnerability CVE-2026-47712 affects version 0.25.2.post1+tuxcare of dulwich, and is fixed in 0.25.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47734 affects version 0.25.2.post1+tuxcare of dulwich, and is fixed in 0.25.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47734"
      },
      "action_statement": "Vulnerability CVE-2026-47734 affects version 0.25.2.post1+tuxcare of dulwich, and is fixed in 0.25.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-52726 affects version 0.25.2.post1+tuxcare of dulwich, and is fixed in 0.25.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-52726"
      },
      "action_statement": "Vulnerability CVE-2026-52726 affects version 0.25.2.post1+tuxcare of dulwich, and is fixed in 0.25.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post1+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-35mr-4567-66vg"
      },
      "action_statement": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post1+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post1+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-5fqc-mrg8-w798"
      },
      "action_statement": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post1+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:19:00.191036+00:00",
      "status_notes": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post1+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8mcx-5rqc-vhmf"
      },
      "action_statement": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post1+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post1+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8w8g-wq8h-fq33"
      },
      "action_statement": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post1+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T18:58:00.304965+00:00",
      "status_notes": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post1+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-cm62-gvxx-vmxx"
      },
      "action_statement": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post1+tuxcare of dulwich."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post4+tuxcare of dulwich.",
      "vulnerability": {
        "name": "AIKIDO-2026-10554"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42305 is fixed in version 0.25.2.post4+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-42305"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42563 is fixed in version 0.25.2.post4+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-42563"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47712 affects version 0.25.2.post4+tuxcare of dulwich, and is fixed in 0.25.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47712"
      },
      "action_statement": "Vulnerability CVE-2026-47712 affects version 0.25.2.post4+tuxcare of dulwich, and is fixed in 0.25.2.post6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47734 is fixed in version 0.25.2.post4+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-47734"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-52726 affects version 0.25.2.post4+tuxcare of dulwich, and is fixed in 0.25.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-52726"
      },
      "action_statement": "Vulnerability CVE-2026-52726 affects version 0.25.2.post4+tuxcare of dulwich, and is fixed in 0.25.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post4+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-35mr-4567-66vg"
      },
      "action_statement": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post4+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post4+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-5fqc-mrg8-w798"
      },
      "action_statement": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post4+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:19:00.191036+00:00",
      "status_notes": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post4+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8mcx-5rqc-vhmf"
      },
      "action_statement": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post4+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post4+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8w8g-wq8h-fq33"
      },
      "action_statement": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post4+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T18:58:00.304965+00:00",
      "status_notes": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post4+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-cm62-gvxx-vmxx"
      },
      "action_statement": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post4+tuxcare of dulwich."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post2+tuxcare of dulwich.",
      "vulnerability": {
        "name": "AIKIDO-2026-10554"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42305 affects version 0.25.2.post2+tuxcare of dulwich, and is fixed in 0.25.2.post3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-42305"
      },
      "action_statement": "Vulnerability CVE-2026-42305 affects version 0.25.2.post2+tuxcare of dulwich, and is fixed in 0.25.2.post3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42563 is fixed in version 0.25.2.post2+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-42563"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47712 affects version 0.25.2.post2+tuxcare of dulwich, and is fixed in 0.25.2.post6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47712"
      },
      "action_statement": "Vulnerability CVE-2026-47712 affects version 0.25.2.post2+tuxcare of dulwich, and is fixed in 0.25.2.post6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47734 affects version 0.25.2.post2+tuxcare of dulwich, and is fixed in 0.25.2.post4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47734"
      },
      "action_statement": "Vulnerability CVE-2026-47734 affects version 0.25.2.post2+tuxcare of dulwich, and is fixed in 0.25.2.post4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-52726 affects version 0.25.2.post2+tuxcare of dulwich, and is fixed in 0.25.2.post5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-52726"
      },
      "action_statement": "Vulnerability CVE-2026-52726 affects version 0.25.2.post2+tuxcare of dulwich, and is fixed in 0.25.2.post5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post2+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-35mr-4567-66vg"
      },
      "action_statement": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post2+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post2+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-5fqc-mrg8-w798"
      },
      "action_statement": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post2+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:19:00.191036+00:00",
      "status_notes": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post2+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8mcx-5rqc-vhmf"
      },
      "action_statement": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post2+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post2+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8w8g-wq8h-fq33"
      },
      "action_statement": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post2+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T18:58:00.304965+00:00",
      "status_notes": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post2+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-cm62-gvxx-vmxx"
      },
      "action_statement": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post2+tuxcare of dulwich."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "AIKIDO-2026-10554"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42305 is fixed in version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-42305"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42563 is fixed in version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-42563"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47712 is fixed in version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-47712"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47734 is fixed in version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-47734"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-52726 is fixed in version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "CVE-2026-52726"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-35mr-4567-66vg"
      },
      "action_statement": "Vulnerability GHSA-35mr-4567-66vg affects version 0.25.2.post6+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-5fqc-mrg8-w798"
      },
      "action_statement": "Vulnerability GHSA-5fqc-mrg8-w798 affects version 0.25.2.post6+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:19:00.191036+00:00",
      "status_notes": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8mcx-5rqc-vhmf"
      },
      "action_statement": "Vulnerability GHSA-8mcx-5rqc-vhmf affects version 0.25.2.post6+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T19:03:00.136739+00:00",
      "status_notes": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-8w8g-wq8h-fq33"
      },
      "action_statement": "Vulnerability GHSA-8w8g-wq8h-fq33 affects version 0.25.2.post6+tuxcare of dulwich."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-02T18:58:00.304965+00:00",
      "status_notes": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post6+tuxcare of dulwich.",
      "vulnerability": {
        "name": "GHSA-cm62-gvxx-vmxx"
      },
      "action_statement": "Vulnerability GHSA-cm62-gvxx-vmxx affects version 0.25.2.post6+tuxcare of dulwich."
    }
  ],
  "@id": "urn:sha256:2e3d9f2abe1d7cc100e8cedbfc84d7cf622374d5804d8dce0152c38bb698c15d"
}
